CVE-2026-100606: Improper Authentication in FlowiseAI Flowise
Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email matching a user whose status is INVITED, verifyAndLogin (SSOBase.ts:80-94) copies the user record from the database — including the server-stored single-use invitation tempToken — into the data passed to AccountService.register(). The register handler's token lookup, email match, and expiry checks therefore pass trivially against the server's own token instead of a caller-supplied one, and the account and its organization membership are flipped to ACTIVE. As a result, anyone able to authenticate at any configured SSO provider using a pending invitee's email address as the email claim can take over that invitation and obtain the invited user's access to the organization without ever possessing the emailed invitation token, for as long as the invitation is valid (24 hours by default). At the time of the advisory no patched version was available.
AI Analysis
Technical Summary
CVE-2026-100606 is an authentication bypass vulnerability in FlowiseAI Flowise (up to version 3.1.4) when operating in Enterprise/platform mode with SSO enabled. The issue occurs in the SSO login callback handling where, if the email claim matches a user with INVITED status, the server copies the user record including the server-stored single-use invitation token into the registration data. The register handler then validates the token against this server-side token rather than a caller-supplied token, causing the checks to pass trivially. Consequently, an attacker who can authenticate via any configured SSO provider with the invited user's email can activate the account and gain organization membership without possessing the emailed invitation token. The invitation validity period is 24 hours by default. No official fix or patch is available at the time of publication.
Potential Impact
An attacker who can authenticate through any configured SSO provider using the email address of a user with a pending invitation can bypass the invitation token requirement and activate the invited account. This grants unauthorized access to the organization with the invited user's privileges for the duration of the invitation validity (default 24 hours). This compromises the integrity of the invitation process and allows privilege escalation without possession of the invitation token.
Mitigation Recommendations
At the time of this advisory, no patch or official fix is available. Users should monitor the vendor's advisory for updates. Until a fix is released, organizations should consider disabling SSO login for invited users or restricting SSO providers to trusted identities to reduce exposure. Avoid relying solely on the invitation token mechanism for authentication in SSO-enabled environments.
CVE-2026-100606: Improper Authentication in FlowiseAI Flowise
Description
Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email matching a user whose status is INVITED, verifyAndLogin (SSOBase.ts:80-94) copies the user record from the database — including the server-stored single-use invitation tempToken — into the data passed to AccountService.register(). The register handler's token lookup, email match, and expiry checks therefore pass trivially against the server's own token instead of a caller-supplied one, and the account and its organization membership are flipped to ACTIVE. As a result, anyone able to authenticate at any configured SSO provider using a pending invitee's email address as the email claim can take over that invitation and obtain the invited user's access to the organization without ever possessing the emailed invitation token, for as long as the invitation is valid (24 hours by default). At the time of the advisory no patched version was available.
CVSS v4.0
Score 9.2critical
Affected software
FlowiseAI
Flowise
pkg:github/flowiseai/FlowiseRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-100606 is an authentication bypass vulnerability in FlowiseAI Flowise (up to version 3.1.4) when operating in Enterprise/platform mode with SSO enabled. The issue occurs in the SSO login callback handling where, if the email claim matches a user with INVITED status, the server copies the user record including the server-stored single-use invitation token into the registration data. The register handler then validates the token against this server-side token rather than a caller-supplied token, causing the checks to pass trivially. Consequently, an attacker who can authenticate via any configured SSO provider with the invited user's email can activate the account and gain organization membership without possessing the emailed invitation token. The invitation validity period is 24 hours by default. No official fix or patch is available at the time of publication.
Potential Impact
An attacker who can authenticate through any configured SSO provider using the email address of a user with a pending invitation can bypass the invitation token requirement and activate the invited account. This grants unauthorized access to the organization with the invited user's privileges for the duration of the invitation validity (default 24 hours). This compromises the integrity of the invitation process and allows privilege escalation without possession of the invitation token.
Mitigation Recommendations
At the time of this advisory, no patch or official fix is available. Users should monitor the vendor's advisory for updates. Until a fix is released, organizations should consider disabling SSO login for invited users or restricting SSO providers to trusted identities to reduce exposure. Avoid relying solely on the invitation token mechanism for authentication in SSO-enabled environments.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:30:34.352Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c99ff7a7c5410652fca2
Added to database: 09/26/2026, 13:33:19 UTC
Last enriched: 09/26/2026, 14:32:40 UTC
Last updated: 09/27/2026, 02:20:01 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.