CVE-2026-91930: Flowise before 3.1.4 Cross-Tenant Organization Admin Takeover

Published Sep 15, 2026
·
Updated

Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints.

Affected Software

1 affected component
Flowise<3.1.4

Event History

Sep 15, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated Flowise user with low privileges can exploit it. The attacker needs to be able to submit requests to the affected organization membership or workspace API endpoints and provide an arbitrary organization ID.

2

Are default or single-tenant deployments affected?

The issue concerns enterprise organization and workspace membership APIs and cross-tenant isolation. The provided information does not establish whether deployments without multiple organizations or tenants are affected.

3

What is the impact if exploitation succeeds?

An attacker can add themselves as an owner of a victim organization, create workspaces, and obtain administrative access to that organization. This can result in high confidentiality, integrity, and availability impact.

4

How can teams determine whether they may already have been affected?

Review organization ownership and membership records for unexpected users, and review workspace creation activity for unauthorized workspaces. Pay particular attention to changes involving organization IDs outside a user's expected tenant.

5

What should be done if immediate patching is not possible?

Restrict access to the affected organizationuser and workspace endpoints to trusted authenticated users where feasible, and monitor or audit membership and workspace changes for cross-tenant activity. The provided information identifies Flowise versions before 3.1.4 as affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203