๐Ÿ” CVE Alert

CVE-2026-90533

UNKNOWN 0.0

Flowise before 3.1.4 Broken Access Control via organizationuser

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash and temporary tokens. Attackers can query the endpoint with any user ID to obtain the owner's credential hash for offline cracking, enabling account takeover of the highest-privileged account.

CWE CWE-862
Vendor flowiseai
Product flowise
Published Sep 12, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for flowiseai flowise

Be the first to know when new unknown vulnerabilities affecting flowiseai flowise are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

FlowiseAI / Flowise
0 < 3.1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-fhxm-xxcx-g6x3 vulncheck.com: https://www.vulncheck.com/advisories/flowise-before-3.1.4-broken-access-control-via-organizationuser

Credits

๐Ÿ” Shirshakhtml