Authentication Bypass Vulnerability in Flowise by FlowiseAI
CVE-2026-100607
9.2CRITICAL
What is CVE-2026-100607?
Flowise versions up to 3.1.4 contain an authentication bypass vulnerability that allows attackers to gain unauthorized access to user accounts. This issue arises because the system resolves both SSO and local-password user accounts solely by email, without adequate bindings to provider or subject identifiers. As a result, attackers can authenticate as any user by merely claiming their email address via any configured SSO provider. Full account access can be compromised, allowing attackers to retrieve sensitive information such as chatflows, credentials, and API keys through a different authentication method than initially used by the user.
Affected Version(s)
Flowise 0 <= 3.1.4
