Skip to main content

CVE-2026-100606: Improper Authentication in FlowiseAI Flowise

0
Critical
VulnerabilityCVE-2026-100606cvecve-2026-100606
Published: 09/26/2026 (09/26/2026, 13:22:49 UTC)
Source: CVE Database V5
Vendor/Project: FlowiseAI
Product: Flowise

Description

Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email matching a user whose status is INVITED, verifyAndLogin (SSOBase.ts:80-94) copies the user record from the database — including the server-stored single-use invitation tempToken — into the data passed to AccountService.register(). The register handler's token lookup, email match, and expiry checks therefore pass trivially against the server's own token instead of a caller-supplied one, and the account and its organization membership are flipped to ACTIVE. As a result, anyone able to authenticate at any configured SSO provider using a pending invitee's email address as the email claim can take over that invitation and obtain the invited user's access to the organization without ever possessing the emailed invitation token, for as long as the invitation is valid (24 hours by default). At the time of the advisory no patched version was available.

CVSS v4.0

Score 9.2critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Affected software

FlowiseAI

Flowise

Affected versions
>=0 <=3.1.4
GitHub Actionsmore threats →ai
flowiseai/Flowise
pkg:github/flowiseai/Flowise
Affected versions
>=0 <=3.1.4

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/26/2026, 14:32:40 UTC

Technical Analysis

CVE-2026-100606 is an authentication bypass vulnerability in FlowiseAI Flowise (up to version 3.1.4) when operating in Enterprise/platform mode with SSO enabled. The issue occurs in the SSO login callback handling where, if the email claim matches a user with INVITED status, the server copies the user record including the server-stored single-use invitation token into the registration data. The register handler then validates the token against this server-side token rather than a caller-supplied token, causing the checks to pass trivially. Consequently, an attacker who can authenticate via any configured SSO provider with the invited user's email can activate the account and gain organization membership without possessing the emailed invitation token. The invitation validity period is 24 hours by default. No official fix or patch is available at the time of publication.

Potential Impact

An attacker who can authenticate through any configured SSO provider using the email address of a user with a pending invitation can bypass the invitation token requirement and activate the invited account. This grants unauthorized access to the organization with the invited user's privileges for the duration of the invitation validity (default 24 hours). This compromises the integrity of the invitation process and allows privilege escalation without possession of the invitation token.

Mitigation Recommendations

At the time of this advisory, no patch or official fix is available. Users should monitor the vendor's advisory for updates. Until a fix is released, organizations should consider disabling SSO login for invited users or restricting SSO providers to trusted identities to reduce exposure. Avoid relying solely on the invitation token mechanism for authentication in SSO-enabled environments.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-26T02:30:34.352Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab7c99ff7a7c5410652fca2

Added to database: 09/26/2026, 13:33:19 UTC

Last enriched: 09/26/2026, 14:32:40 UTC

Last updated: 09/27/2026, 02:20:01 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses