ZeroHour

CVE-2026-91929

niche

Cross-Tenant Authorization Bypass in Flowise Enterprise (pre-3.1.4)

CVSS 4.0
7.6 high
EPSS
Published
()
Modified
AI analysis

Flowise versions before 3.1.4 contain missing authorization checks (CWE-862) on Enterprise multi-tenant endpoints that fail to verify whether the requesting user owns the target resource. An authenticated attacker with any level of Enterprise access can exploit these gaps to delete arbitrary workspaces, invite themselves into other organizations, and modify cross-organization role assignments. The flaw also exposes stored SSO secrets, which an attacker could abuse to impersonate identity providers or pivot into federated accounts. Affected deployments are limited to Flowise Enterprise (multi-tenant) installations running versions prior to 3.1.4; the community/single-tenant edition is not exposed to these Enterprise endpoints. No public proof of concept exists and the vulnerability is not listed in CISA's KEV catalog, so no exploitation is currently known.

What to do: Upgrade Flowise Enterprise to version 3.1.4 or later, which adds resource-ownership verification on the affected endpoints. Because stored SSO secrets can be abused, rotate all SSO/OAuth client secrets and review IdP logs for anomalous authentications. Audit workspace deletion events, cross-org invitations, and role changes since the deployment's upgrade baseline to detect any prior abuse.

Affected
FlowiseAI Flowise (Enterprise edition)all versions before 3.1.4
Estimated exposure
nichelikely hundreds of Enterprise-licensed organizations; a few thousand internet-exposed Flowise instances overall, of which only the Enterprise multi-tenant… — Public scan data typically shows low thousands of internet-reachable Flowise instances for this self-hosted open-source project, and the vulnerable code paths require a paid Enterprise license, so only a small fraction of deployments are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets.

Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.