Description
Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash and temporary tokens. Attackers can query the endpoint with any user ID to obtain the owner's credential hash for offline cracking, enabling account takeover of the highest-privileged account.
Published: 2026-09-12
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Account Takeover via credential theft
Action: Patch
AI Analysis

Impact

Flowise versions contain a broken access control flaw in the /api/v1/organizationuser GET endpoint. The flaw allows any authenticated organization member to query any user ID and receive the full user record for the organization owner, including the bcrypt password hash and temporary tokens. Because the weakness is a classic lack of proper authorization checks (CWE-862), an attacker with common organizational privileges can obtain credential material and perform offline cracking or direct reuse, enabling compromise of the highest‑privileged account.

Affected Systems

Affected products are Flowise with all releases prior to 3.1.4. No specific sub‑product or environment details are given beyond the overall product line.

Risk and Exploitability

The CVSS score of 6.0 classifies this as a medium impact flaw, but the potential for credential theft and subsequent account takeover makes it high in practical risk. EPSS score is low at <1%, indicating a minimal but non‑zero likelihood of exploitation, but this does not absolve the need for mitigation. The vulnerability is not listed in CISA’s KEV catalog, indicating no known large‑scale public exploitation yet, increases the value to attackers. Attacker likely need only a valid organization member account; once authenticated request.

Generated by OpenCVE AI on September 15, 2026 at 18:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Flowise to version 3.1.4 to fix the broken access control flaw.
  • Revoke or disable any temporary tokens issued by the organization owner and rotate the organization owner’s password to invalidate the stolen hash and associated sessions.
  • Apply a configuration change to the /api/v1/organizationuser endpoint so that only organization owners can access it, rejecting requests from other authenticated members.
  • Review audit logs for evidence of unauthorized access to the endpoint and investigate any suspicious activity.

Generated by OpenCVE AI on September 15, 2026 at 18:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash and temporary tokens. Attackers can query the endpoint with any user ID to obtain the owner's credential hash for offline cracking, enabling account takeover of the highest-privileged account.
Title Flowise before 3.1.4 Broken Access Control via organizationuser
First Time appeared Flowiseai
Flowiseai flowise
Weaknesses CWE-862
CPEs cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Vendors & Products Flowiseai
Flowiseai flowise
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Flowiseai Flowise
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T18:29:22.757Z

Reserved: 2026-09-12T11:12:50.791Z

Link: CVE-2026-90533

cve-icon Vulnrichment

Updated: 2026-09-14T18:29:17.879Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-12T13:16:51.100

Modified: 2026-09-15T18:23:42.930

Link: CVE-2026-90533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:15:11Z

Weaknesses