Description
Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets.
Published: 2026-09-15
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross-tenant authorization bypass
Action: Immediate patch
AI Analysis

Impact

Flowise versions before 3.1.4 contain authorization gaps in Enterprise endpoints that do not verify resource ownership before performing operations. This deficiency allows an attacker with Enterprise access to delete arbitrary workspaces, invite themselves into other organizations, alter cross‑organization roles, and abuse stored SSO secrets; the weakness is classified as CWE‑862.

Affected Systems

The product affected is Flowise by FlowiseAI. All releases before version 3.1.4 are vulnerable. No other product or version details are specified.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity. Attackers must first obtain or already possess Enterprise privileges, which limits the attack surface to privileged users or compromised accounts. Since the EPSS score is < 1% and the vulnerability is not in the CISA KEV catalog, the exploitation probability is uncertain but the potential impact across tenants is significant.

Generated by OpenCVE AI on September 20, 2026 at 16:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Flowise update (≥3.1.4) to eliminate the cross‑tenant authorization gaps.
  • Restrict or disable Enterprise endpoint access for users that do not require it until the update is applied.
  • Review and revoke any SSO secrets, roles, or workspace memberships that may have been abused, and enforce audit logging for cross‑tenant operations.

Generated by OpenCVE AI on September 20, 2026 at 16:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets.
Title Flowise before 3.1.4 Cross-Tenant Authorization Bypass
First Time appeared Flowiseai
Flowiseai flowise
Weaknesses CWE-862
CPEs cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Vendors & Products Flowiseai
Flowiseai flowise
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Flowiseai Flowise
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T15:44:41.985Z

Reserved: 2026-09-15T11:06:02.262Z

Link: CVE-2026-91929

cve-icon Vulnrichment

Updated: 2026-09-15T15:44:39.600Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:43.187

Modified: 2026-09-23T17:17:47.040

Link: CVE-2026-91929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses