Authentication Bypass in Flowise Enterprise Mode with SSO Enabled
CVE-2026-100606
What is CVE-2026-100606?
Flowise versions through 3.1.4 are susceptible to an authentication bypass vulnerability when Single Sign-On (SSO) is enabled in enterprise/platform mode. The issue arises in the SSO login pathway, where an SSO callback can match an email associated with a user in an 'INVITED' status. The flaw permits the copying of user records, including a tempToken from the database, thereby bypassing crucial checks on the validity of the invitation. This allows individuals who authenticate via any configured SSO provider with only the email claim of an invited user to gain access to the user's account and associated organization rights. This unauthorized access can persist for the duration of the invitation's validity, typically 24 hours. There are no patches available as of the advisory date.
Affected Version(s)
Flowise 0 <= 3.1.4
