Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.7
CVE-2026-91930: Flowise before 3.1.4 lets users hijack other organizations
CVE-2026-91930 · published 24 days ago
Summary
In versions of Flowise earlier than 3.1.4, the system does not correctly limit certain management functions to the user's own company. A logged‑in user can trick the software into treating them as an owner of another company's account, creating workspaces and gaining full control. Upgrade to version 3.1.4 or later to stop this behavior.
What to do
- Update flowiseai flowise to version 3.1.4 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| flowiseai | flowise | < 3.1.4 |
Original advisory text
Flowise before 3.1.4 Cross-Tenant Organization Admin Takeover
Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91930... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-91930 Vendor Advisory
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-pprx-4prj-35mj
- https://www.vulncheck.com/advisories/flowise-before-3.1.4-cross-tenant-organizat...
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
7.7
High
Type
CWE-266Incorrect Privilege Assignment
Timeline
Published15 Sep 2026
Updated9 Oct 2026
First seen15 Sep 2026
Track software like this
Free during beta