Authorization Bypass in Flowise Through 3.1.4 Affects BullMQ Admin Dashboard
CVE-2026-100608
What is CVE-2026-100608?
Flowise versions up to 3.1.4 exhibit a significant authorization bypass flaw within the BullMQ admin dashboard. When this server is configured to operate in queue mode with the dashboard active and not using cloud mode, the necessary authorization checks are inadequately enforced. Specifically, the dashboard's /admin/queues endpoint relies solely on a JWT verification middleware without implementing role or permission restrictions. This exposes sensitive information and administrative functionality to any authenticated user, regardless of their privilege level. As a consequence, all tenants may gain visibility into and perform actions across shared resources, which potentially includes confidential data such as system prompts and credential IDs. Currently, no patch is available to address this vulnerability.
Affected Version(s)
Flowise 0 <= 3.1.4
