Authentication Bypass Vulnerability in Flowise by FlowiseAI
CVE-2026-100607

9.2CRITICAL

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100607?

Flowise versions up to 3.1.4 contain an authentication bypass vulnerability that allows attackers to gain unauthorized access to user accounts. This issue arises because the system resolves both SSO and local-password user accounts solely by email, without adequate bindings to provider or subject identifiers. As a result, attackers can authenticate as any user by merely claiming their email address via any configured SSO provider. Full account access can be compromised, allowing attackers to retrieve sensitive information such as chatflows, credentials, and API keys through a different authentication method than initially used by the user.

Affected Version(s)

Flowise 0 <= 3.1.4

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

amwhoi
.