PT-2026-99277 · Flowise · Flowise

·

CVE-2026-100606

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.5
Description An authentication bypass exists in the SSO login path when Enterprise/platform mode with SSO is enabled. The issue occurs when an SSO callback is received with an email matching a user with an INVITED status. The verifyAndLogin() function in SSOBase.ts copies the user record, including the server-stored single-use tempToken, into the data sent to AccountService.register(). This causes the token lookup, email match, and expiry checks to pass using the server's own token rather than a token provided by the caller, resulting in the account and organization membership being set to ACTIVE. Consequently, an attacker who can authenticate via a configured SSO provider using a pending invitee's email address can take over the invitation and gain access to the organization without the invitation token, provided the invitation is still valid.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100606
GHSA-VF3J-89VF-R697

Affected Products

Flowise