Skip to content
Threat Feed
high advisory

Flowise Cross-Tenant Authorization Vulnerability

Flowise versions before 3.1.4 contain authorization gaps in Enterprise endpoints that allow authenticated users to perform cross-tenant operations including unauthorized workspace deletion and SSO credential access.

CVE search metadata

CVE search record: CVE-2026-91929. Severity: high. CVSS: 7.1. KEV: no. Product: Flowise Enterprise (< 3.1.4), Flowise (< 3.1.4). Brief: Flowise Cross-Tenant Authorization Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-09-flowise-auth-gap/

What's new

  • 1. added coverage for Flowise (< 3.1.4) Sep 15, 21:53 via nvd
  • 2. added coverage for Flowise (< 3.1.4) Sep 15, 19:42 via nvd
  • 3. added coverage for Flowise (< 3.1.4) Sep 15, 17:43 via nvd
  • 4. added coverage for Flowise (< 3.1.4) Sep 15, 17:43 via nvd
  • 5. added coverage for Flowise (< 3.1.4) Sep 15, 17:43 via nvd

Flowise versions prior to 3.1.4 are affected by critical cross-tenant authorization flaws within their Enterprise endpoint implementations. The vulnerability arises from a failure to validate resource ownership during API operations. An attacker who has legitimate access to an Enterprise instance can exploit these endpoints to interact with resources belonging to other tenants within the same installation.

Successful exploitation allows for a range of unauthorized activities, including the deletion of arbitrary workspaces, unauthorized self-invitation into external organizations, modification of cross-organization roles, and the retrieval of stored Single Sign-On (SSO) secrets. Given the potential for complete control over tenant configuration and the exposure of sensitive authentication material, this vulnerability poses a high risk to organizations utilizing Flowise Enterprise.

Impact

The vulnerability allows authenticated attackers to compromise the confidentiality, integrity, and availability of multi-tenant Flowise environments. Impact includes the destruction of victim workspace data, potential account takeovers via cross-org role escalation, and the compromise of sensitive SSO configuration secrets, which could lead to further downstream attacks against integrated corporate identity providers.

Recommendation

  • Update all Flowise Enterprise instances to version 3.1.4 or later immediately.
  • Review audit logs for anomalous API requests targeting organization management endpoints or role modifications that appear outside of authorized administrative workflows.
  • Monitor for unauthorized workspace deletions or suspicious additions of new users to high-privilege organization roles.
  • Rotate all SSO secrets and configuration keys stored within Flowise Enterprise if there is suspicion that an unauthenticated or unauthorized actor accessed the system prior to patching.

Immediate actions

Patch Flowise Enterprise to 3.1.4

IT Operations 24h

Mitigations

Upgrade to 3.1.4

immediate IT Operations

CVE-2026-91929