cvedb.io
CVE-2026-33879
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2026-03-27T21:17:24.537 · Last modified 2026-06-17T10:38:14.917

Summary

Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models across healthcare institutions. The FLIP login page in versions 0.1.1 and prior has no rate limiting or CAPTCHA, enabling brute-force and credential-stuffing attacks. FLIP users are external to the organization, increasing credential reuse risk. As of time of publication, it is unclear if a patch is available.

Affected products

aicentre — federated_learning_and_interoperability_platform

Does this affect you?

Add your gear to cvedb and we'll alert you only when aicentre ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.