PT-2026-82625 · Flowintel · Flowintel
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Flowintel versions 3.3.0 and later
Description
An authorization flaw exists in the administrative user-edit API. While the system prevents organization administrators from editing users in different organizations, it fails to restrict them from modifying full administrator accounts within their own organization. This allows an organization administrator to change the password of a full administrator, leading to privilege escalation. The issue is addressed by implementing a privilege boundary check using the
is admin() function to block these modifications.Recommendations
Update Flowintel to a version where the
is admin() boundary check is implemented in the user-edit API to prevent organization administrators from modifying full administrator accounts.Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flowintel