Authentication Bypass in Flowise Enterprise Mode with SSO Enabled
CVE-2026-100606

9.2CRITICAL

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100606?

Flowise versions through 3.1.4 are susceptible to an authentication bypass vulnerability when Single Sign-On (SSO) is enabled in enterprise/platform mode. The issue arises in the SSO login pathway, where an SSO callback can match an email associated with a user in an 'INVITED' status. The flaw permits the copying of user records, including a tempToken from the database, thereby bypassing crucial checks on the validity of the invitation. This allows individuals who authenticate via any configured SSO provider with only the email claim of an invited user to gain access to the user's account and associated organization rights. This unauthorized access can persist for the duration of the invitation's validity, typically 24 hours. There are no patches available as of the advisory date.

Affected Version(s)

Flowise 0 <= 3.1.4

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

amwhoi
.