CVE-2026-91930: Flowise before 3.1.4 Cross-Tenant Organization Admin Takeover
Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated Flowise user with low privileges can exploit it. The attacker needs to be able to submit requests to the affected organization membership or workspace API endpoints and provide an arbitrary organization ID.
Are default or single-tenant deployments affected?
The issue concerns enterprise organization and workspace membership APIs and cross-tenant isolation. The provided information does not establish whether deployments without multiple organizations or tenants are affected.
What is the impact if exploitation succeeds?
An attacker can add themselves as an owner of a victim organization, create workspaces, and obtain administrative access to that organization. This can result in high confidentiality, integrity, and availability impact.
How can teams determine whether they may already have been affected?
Review organization ownership and membership records for unexpected users, and review workspace creation activity for unauthorized workspaces. Pay particular attention to changes involving organization IDs outside a user's expected tenant.
What should be done if immediate patching is not possible?
Restrict access to the affected organizationuser and workspace endpoints to trusted authenticated users where feasible, and monitor or audit membership and workspace changes for cross-tenant activity. The provided information identifies Flowise versions before 3.1.4 as affected.