{
  "title": "CVE del giorno — CVE-2026-56271 (CVSS 9,8, critica)",
  "title_variants": [
    {
      "id": "v0",
      "title": "CVE del giorno — CVE-2026-56271 (CVSS 9,8, critica)"
    },
    {
      "id": "v1",
      "title": "CVE-2026-56271: vulnerabilità critica, CVSS 9,8/10, tipo CWE-321, sfruttabile da"
    }
  ],
  "description": "CVE-2026-56271: vulnerabilità critica, CVSS 9,8/10, tipo CWE-321, sfruttabile da remoto, senza privilegi, senza interazione utente. Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer…",
  "keywords": [
    "cve",
    "cve-2026-56271",
    "vulnerabilità",
    "vulnerabilità critica",
    "cwe-321",
    "cvss",
    "sicurezza informatica",
    "cybersecurity",
    "nvd",
    "aggiornamento di sicurezza"
  ],
  "scenes": [
    {
      "title": "CVE-2026-56271",
      "subtitle": "CVSS 9,8",
      "text": "CVE-2026-56271: gravità critica, punteggio CVSS 9,8 su 10 secondo il National Vulnerability Database."
    },
    {
      "title": "CWE-321",
      "subtitle": "CWE-321 · CVSS v3.1",
      "text": "Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise…"
    },
    {
      "title": "ESPOSIZIONE E MITIGAZIONE",
      "subtitle": "sfruttabile da remoto, senza privilegi, senza interazione utente",
      "text": "Vulnerabilità sfruttabile da remoto, senza privilegi, senza interazione utente. Applica tempestivamente l'aggiornamento del fornitore e consulta l'avviso ufficiale su NVD."
    }
  ],
  "publication_date": "2026-07-20T00:21:21.738Z",
  "duration": 20,
  "topic": "cve",
  "lang": "it",
  "translation_group": "cve-2026-07-14",
  "poster": "cve-2026-07-14.jpg",
  "preview": "cve-2026-07-14.gif",
  "og_card": "cve-2026-07-14.og.jpg",
  "audiogram": "cve-2026-07-14.audiogram.mp4",
  "captions": "cve-2026-07-14.vtt",
  "generation": {
    "procedural": true,
    "ai_generated": [
      "background",
      "voice"
    ],
    "real_data_source": "official public API",
    "filmed_real_event": false,
    "disclosure": "Procedurally generated from real public-source data; abstract AI-generated backgrounds; synthetic (TTS) voice. No real event is filmed or altered."
  },
  "transcript_text": "CVE-2026-56271: gravità critica, punteggio CVSS 9,8 su 10 secondo il National Vulnerability Database. Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise… Vulnerabilità sfruttabile da remoto, senza privilegi, senza interazione utente. Applica tempestivamente l'aggiornamento del fornitore e consulta l'avviso ufficiale su NVD.",
  "transcript": [
    {
      "start": 0,
      "end": 6.667,
      "text": "CVE-2026-56271: gravità critica, punteggio CVSS 9,8 su 10 secondo il National Vulnerability Database."
    },
    {
      "start": 6.667,
      "end": 13.333,
      "text": "Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise…"
    },
    {
      "start": 13.333,
      "end": 20,
      "text": "Vulnerabilità sfruttabile da remoto, senza privilegi, senza interazione utente. Applica tempestivamente l'aggiornamento del fornitore e consulta l'avviso ufficiale su NVD."
    }
  ]
}