Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.7

CVE-2026-91930: Flowise before 3.1.4 lets users hijack other organizations

CVE-2026-91930 · published 24 days ago
Summary

In versions of Flowise earlier than 3.1.4, the system does not correctly limit certain management functions to the user's own company. A logged‑in user can trick the software into treating them as an owner of another company's account, creating workspaces and gaining full control. Upgrade to version 3.1.4 or later to stop this behavior.

What to do
  • Update flowiseai flowise to version 3.1.4 or later.
Affected software
VendorProductAffected versions
flowiseai flowise < 3.1.4
Original advisory text
Flowise before 3.1.4 Cross-Tenant Organization Admin Takeover
Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
7.7 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-266Incorrect Privilege Assignment
Timeline
Published15 Sep 2026
Updated9 Oct 2026
First seen15 Sep 2026
Sources
CVE-2026-91930 · MITRE
Track software like this
Free during beta