Improperly Controlled Modification of Dynamically-Determined Object Attributes in Flowise - CVE-2026-41267
Published: May 4, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized cross-tenant access and escalate privileges.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the account registration endpoint when processing registration requests. A remote attacker can send a specially crafted request containing injected server-managed fields and nested objects to gain unauthorized cross-tenant access and escalate privileges.
The issue affects multi-tenant deployments and can allow unauthorized association of a newly created account with an existing organization during registration.