Cross-Tenant Organization Admin Takeover in Flowise by FlowiseAI
CVE-2026-91930
7.7HIGH
What is CVE-2026-91930?
Flowise versions prior to 3.1.4 exhibit a significant security flaw that permits authenticated users to exploit inadequacies in tenant isolation. This allows potential attackers to input arbitrary organization IDs, effectively becoming organization owners. As a consequence, they can create new workspaces and obtain unauthorized administrative access to affected organizations. Such a vulnerability highlights the critical need for robust API scoping and tenant isolation to prevent unauthorized access and maintain organizational integrity.
Affected Version(s)
Flowise 0 < 3.1.4
Flowise 3.1.4
