Flowise · Flowise · CVE-2026-100608
**Name of the Vulnerable Software and Affected Versions**
Flowise versions prior to 3.1.5
**Description**
When the server operates in queue mode with the dashboard enabled and is not in cloud mode (`MODE=queue`, `ENABLE BULLMQ DASHBOARD=true`, and `!isCloud()`), the `/admin/queues` endpoint is protected only by the `verifyTokenForBullMQDashboard` middleware. This middleware validates the JSON Web Token (JWT) but fails to perform role, permission, or workspace/organization scoping checks. Additionally, because the mount is located outside the `/api/v1/*` path, the global API gate is not applied. Consequently, any authenticated user, regardless of their privilege level or tenant, can access the Bull-Board UI to view all queues and job payloads across the entire instance. This exposure includes chat inputs, `overrideConfig` (which may contain credentials and prompts), `chatflow.flowData` graph definitions with custom function source code, credential IDs, system prompts, `chatIds`, files, and the originating `orgId`/`workspaceId`. Furthermore, write actions such as retry, remove, promote, and clean are accessible across all tenants.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider disabling the BullMQ dashboard by setting `ENABLE BULLMQ DASHBOARD=false` to minimize the risk of exploitation.