PT-2026-92050 · Flowise · Flowise
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Flowise versions prior to 3.1.4
Description
Insufficient tenant isolation in the enterprise organization and workspace membership APIs allows authenticated users to provide arbitrary organization IDs. This flaw enables attackers to add themselves as organization owners, create workspaces, and obtain administrative access to victim organizations via the
organizationuser and workspace endpoints.Recommendations
Update to version 3.1.4 or later.
Exploit
Fix
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flowise