Impact
The flaw is an authorization weakness that lets an organization administrator change the password of a full administrator account in the same organization. This allows the organization administrator to gain full administrator privileges by resetting a privileged account’s credentials, compromising confidentiality and integrity of the entire system. The vulnerability is a classic example of CWE-269, Unauthorized Access Through Privilege Escalation.
Affected Systems
Flowintel’s web application is affected starting with version 3.3.0 and later releases that contain the unpatched authorization check, allowing any org‑admin role within the application to modify full‑admin users in their own organization.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity with significant impact if exploited. The EPSS score is not available, so the current exploitation probability is unknown, but the vulnerability is not recorded in CISA’s KEV list. The likely attack vector is via the privileged administrative API exposed over the network; an attacker must have org‑admin credentials and API access, which is typically available to legitimate users. Once exploited, the attacker can reset a full administrator password and assume unrestricted control over the system.
OpenCVE Enrichment