PT-2026-82625 · Flowintel · Flowintel

·

CVE-2026-81818

·

Published

2026-08-27

·

Updated

2026-08-28

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Flowintel versions 3.3.0 and later
Description An authorization flaw exists in the administrative user-edit API. While the system prevents organization administrators from editing users in different organizations, it fails to restrict them from modifying full administrator accounts within their own organization. This allows an organization administrator to change the password of a full administrator, leading to privilege escalation. The issue is addressed by implementing a privilege boundary check using the is admin() function to block these modifications.
Recommendations Update Flowintel to a version where the is admin() boundary check is implemented in the user-edit API to prevent organization administrators from modifying full administrator accounts.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81818

Affected Products

Flowintel