Flowise Cross-Tenant Authorization Vulnerability
Flowise versions before 3.1.4 contain authorization gaps in Enterprise endpoints that allow authenticated users to perform cross-tenant operations including unauthorized workspace deletion and SSO credential access.
CVE search metadata
CVE search record: CVE-2026-91929. Severity: high. CVSS: 7.1. KEV: no. Product: Flowise Enterprise (< 3.1.4), Flowise (< 3.1.4). Brief: Flowise Cross-Tenant Authorization Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-09-flowise-auth-gap/
What's new
- 1. added coverage for Flowise (< 3.1.4) Sep 15, 21:53 via nvd
- 2. added coverage for Flowise (< 3.1.4) Sep 15, 19:42 via nvd
- 3. added coverage for Flowise (< 3.1.4) Sep 15, 17:43 via nvd
- 4. added coverage for Flowise (< 3.1.4) Sep 15, 17:43 via nvd
- 5. added coverage for Flowise (< 3.1.4) Sep 15, 17:43 via nvd
Flowise versions prior to 3.1.4 are affected by critical cross-tenant authorization flaws within their Enterprise endpoint implementations. The vulnerability arises from a failure to validate resource ownership during API operations. An attacker who has legitimate access to an Enterprise instance can exploit these endpoints to interact with resources belonging to other tenants within the same installation.
Successful exploitation allows for a range of unauthorized activities, including the deletion of arbitrary workspaces, unauthorized self-invitation into external organizations, modification of cross-organization roles, and the retrieval of stored Single Sign-On (SSO) secrets. Given the potential for complete control over tenant configuration and the exposure of sensitive authentication material, this vulnerability poses a high risk to organizations utilizing Flowise Enterprise.
Impact
The vulnerability allows authenticated attackers to compromise the confidentiality, integrity, and availability of multi-tenant Flowise environments. Impact includes the destruction of victim workspace data, potential account takeovers via cross-org role escalation, and the compromise of sensitive SSO configuration secrets, which could lead to further downstream attacks against integrated corporate identity providers.
Recommendation
- Update all Flowise Enterprise instances to version 3.1.4 or later immediately.
- Review audit logs for anomalous API requests targeting organization management endpoints or role modifications that appear outside of authorized administrative workflows.
- Monitor for unauthorized workspace deletions or suspicious additions of new users to high-privilege organization roles.
- Rotate all SSO secrets and configuration keys stored within Flowise Enterprise if there is suspicion that an unauthenticated or unauthorized actor accessed the system prior to patching.
Immediate actions
Patch Flowise Enterprise to 3.1.4
Mitigations
Upgrade to 3.1.4
CVE-2026-91929