Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 16:17
Updated : 2026-09-15 16:17
NVD link : CVE-2026-91930
Mitre link : CVE-2026-91930
CVE.ORG link : CVE-2026-91930
JSON object : View
Products Affected
No product.
CWE
CWE-266
Incorrect Privilege Assignment
