Cross-Tenant Authorization Gaps in Flowise by FlowiseAI
CVE-2026-91929

7.6HIGH

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91929?

The affected versions of Flowise, prior to 3.1.4, exhibit serious cross-tenant authorization gaps within their Enterprise endpoints. These weaknesses allow users with Enterprise access to perform operations without verifying resource ownership, potentially leading to significant security risks. Attackers can delete arbitrary workspaces, gain unauthorized access to other organizations, manipulate cross-organization roles, and misuse stored Single Sign-On (SSO) secrets.

Affected Version(s)

Flowise 0 < 3.1.4

Flowise 3.1.4

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

park0407
.