Authorization Bypass in Flowise Through 3.1.4 Affects BullMQ Admin Dashboard
CVE-2026-100608

8.7HIGH

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100608?

Flowise versions up to 3.1.4 exhibit a significant authorization bypass flaw within the BullMQ admin dashboard. When this server is configured to operate in queue mode with the dashboard active and not using cloud mode, the necessary authorization checks are inadequately enforced. Specifically, the dashboard's /admin/queues endpoint relies solely on a JWT verification middleware without implementing role or permission restrictions. This exposes sensitive information and administrative functionality to any authenticated user, regardless of their privilege level. As a consequence, all tenants may gain visibility into and perform actions across shared resources, which potentially includes confidential data such as system prompts and credential IDs. Currently, no patch is available to address this vulnerability.

Affected Version(s)

Flowise 0 <= 3.1.4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

amwhoi
.