Description
Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API.


The existing authorization check correctly prevented an organization administrator from editing users in another organization, but it did not prevent them from editing a full administrator within their own organization. As a result, an org admin could modify that full administrator account, including changing its password. The upstream commit explicitly describes the issue as:


“Org admin can change the password of a full admin in the same organization.”


The fix adds a higher-privilege boundary check:


if user_to_edit.is_admin(): return ... 403

so organization administrators can no longer modify full administrator accounts.

Version impacted >=3.3.0
Published: 2026-08-27
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an authorization weakness that lets an organization administrator change the password of a full administrator account in the same organization. This allows the organization administrator to gain full administrator privileges by resetting a privileged account’s credentials, compromising confidentiality and integrity of the entire system. The vulnerability is a classic example of CWE-269, Unauthorized Access Through Privilege Escalation.

Affected Systems

Flowintel’s web application is affected starting with version 3.3.0 and later releases that contain the unpatched authorization check, allowing any org‑admin role within the application to modify full‑admin users in their own organization.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity with significant impact if exploited. The EPSS score is not available, so the current exploitation probability is unknown, but the vulnerability is not recorded in CISA’s KEV list. The likely attack vector is via the privileged administrative API exposed over the network; an attacker must have org‑admin credentials and API access, which is typically available to legitimate users. Once exploited, the attacker can reset a full administrator password and assume unrestricted control over the system.

Generated by OpenCVE AI on August 27, 2026 at 19:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch that adds the is_admin() boundary check to the user‑edit API so organization administrators cannot modify full administrator accounts.
  • If an immediate patch is not available, restrict organization administrator privileges or remove the Docker API access to the user‑edit endpoint until the patch is applied.
  • Continuously monitor audit logs for unexpected changes to administrator passwords and track any privilege escalation events.

Generated by OpenCVE AI on August 27, 2026 at 19:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Flowintel
Flowintel flowintel
Vendors & Products Flowintel
Flowintel flowintel

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API. The existing authorization check correctly prevented an organization administrator from editing users in another organization, but it did not prevent them from editing a full administrator within their own organization. As a result, an org admin could modify that full administrator account, including changing its password. The upstream commit explicitly describes the issue as: “Org admin can change the password of a full admin in the same organization.” The fix adds a higher-privilege boundary check: if user_to_edit.is_admin(): return ... 403 so organization administrators can no longer modify full administrator accounts. Version impacted >=3.3.0
Title Flowintel Organization Administrator Can Reset Full Administrator Password and Escalate Privileges
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Flowintel Flowintel
cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-08-27T19:42:43.350Z

Reserved: 2026-08-27T13:14:18.676Z

Link: CVE-2026-81818

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T17:21:05.340

Modified: 2026-08-27T20:18:55.920

Link: CVE-2026-81818

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T19:15:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management