CVE-2026-91929
nicheCross-Tenant Authorization Bypass in Flowise Enterprise (pre-3.1.4)
Flowise versions before 3.1.4 contain missing authorization checks (CWE-862) on Enterprise multi-tenant endpoints that fail to verify whether the requesting user owns the target resource. An authenticated attacker with any level of Enterprise access can exploit these gaps to delete arbitrary workspaces, invite themselves into other organizations, and modify cross-organization role assignments. The flaw also exposes stored SSO secrets, which an attacker could abuse to impersonate identity providers or pivot into federated accounts. Affected deployments are limited to Flowise Enterprise (multi-tenant) installations running versions prior to 3.1.4; the community/single-tenant edition is not exposed to these Enterprise endpoints. No public proof of concept exists and the vulnerability is not listed in CISA's KEV catalog, so no exploitation is currently known.
What to do: Upgrade Flowise Enterprise to version 3.1.4 or later, which adds resource-ownership verification on the affected endpoints. Because stored SSO secrets can be abused, rotate all SSO/OAuth client secrets and review IdP logs for anomalous authentications. Audit workspace deletion events, cross-org invitations, and role changes since the deployment's upgrade baseline to detect any prior abuse.
| FlowiseAI Flowise (Enterprise edition) | all versions before 3.1.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets.
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.