No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets. | |
| Title | Flowise before 3.1.4 Cross-Tenant Authorization Bypass | |
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:44:41.985Z
Reserved: 2026-09-15T11:06:02.262Z
Link: CVE-2026-91929
Updated: 2026-09-15T15:44:39.600Z
Status : Received
Published: 2026-09-15T16:17:43.187
Modified: 2026-09-15T16:17:43.187
Link: CVE-2026-91929
No data.
OpenCVE Enrichment
Updated: 2026-09-15T18:00:16Z
-
CWE-862
Missing Authorization