Cross-Tenant Authorization Gaps in Flowise by FlowiseAI
CVE-2026-91929
7.6HIGH
What is CVE-2026-91929?
The affected versions of Flowise, prior to 3.1.4, exhibit serious cross-tenant authorization gaps within their Enterprise endpoints. These weaknesses allow users with Enterprise access to perform operations without verifying resource ownership, potentially leading to significant security risks. Attackers can delete arbitrary workspaces, gain unauthorized access to other organizations, manipulate cross-organization roles, and misuse stored Single Sign-On (SSO) secrets.
Affected Version(s)
Flowise 0 < 3.1.4
Flowise 3.1.4
