{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/flowise-enterprise--3.1.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:flowiseai:flowise:*:*:*:*:enterprise:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-91929"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Flowise Enterprise (\u003c 3.1.4)","Flowise (\u003c 3.1.4)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","arbitrary-file-write","rce","xss","vulnerability","nosql-injection","web-application","ssrf","privilege-escalation","tenant-isolation","api-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Flowise"],"content_html":"\u003cp\u003eFlowise versions prior to 3.1.4 are affected by critical cross-tenant authorization flaws within their Enterprise endpoint implementations. The vulnerability arises from a failure to validate resource ownership during API operations. An attacker who has legitimate access to an Enterprise instance can exploit these endpoints to interact with resources belonging to other tenants within the same installation.\u003c/p\u003e\n\u003cp\u003eSuccessful exploitation allows for a range of unauthorized activities, including the deletion of arbitrary workspaces, unauthorized self-invitation into external organizations, modification of cross-organization roles, and the retrieval of stored Single Sign-On (SSO) secrets. Given the potential for complete control over tenant configuration and the exposure of sensitive authentication material, this vulnerability poses a high risk to organizations utilizing Flowise Enterprise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows authenticated attackers to compromise the confidentiality, integrity, and availability of multi-tenant Flowise environments. Impact includes the destruction of victim workspace data, potential account takeovers via cross-org role escalation, and the compromise of sensitive SSO configuration secrets, which could lead to further downstream attacks against integrated corporate identity providers.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all Flowise Enterprise instances to version 3.1.4 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview audit logs for anomalous API requests targeting organization management endpoints or role modifications that appear outside of authorized administrative workflows.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized workspace deletions or suspicious additions of new users to high-privilege organization roles.\u003c/li\u003e\n\u003cli\u003eRotate all SSO secrets and configuration keys stored within Flowise Enterprise if there is suspicion that an unauthenticated or unauthorized actor accessed the system prior to patching.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T21:53:16Z","date_published":"2026-09-15T17:42:48Z","id":"https://feed.craftedsignal.io/briefs/2026-09-flowise-auth-gap/","summary":"Flowise versions before 3.1.4 contain authorization gaps in Enterprise endpoints that allow authenticated users to perform cross-tenant operations including unauthorized workspace deletion and SSO credential access.","title":"Flowise Cross-Tenant Authorization Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-flowise-auth-gap/"}],"language":"en","title":"CraftedSignal Threat Feed - Flowise Enterprise (\u003c 3.1.4)","version":"https://jsonfeed.org/version/1.1"}