Cross-Tenant Organization Admin Takeover in Flowise by FlowiseAI
CVE-2026-91930

7.7HIGH

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91930?

Flowise versions prior to 3.1.4 exhibit a significant security flaw that permits authenticated users to exploit inadequacies in tenant isolation. This allows potential attackers to input arbitrary organization IDs, effectively becoming organization owners. As a consequence, they can create new workspaces and obtain unauthorized administrative access to affected organizations. Such a vulnerability highlights the critical need for robust API scoping and tenant isolation to prevent unauthorized access and maintain organizational integrity.

Affected Version(s)

Flowise 0 < 3.1.4

Flowise 3.1.4

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

huslayer826
.