Authorization bypass through user-controlled key in Flowise - CVE-2026-90534

 

Authorization bypass through user-controlled key in Flowise - CVE-2026-90534

Published: August 31, 2026 / Updated: September 14, 2026


Vulnerability identifier: #VU146336
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90534
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information from third-party resources across workspace boundaries.

The vulnerability exists due to authorization bypass through a user-controlled key in the node-load-method endpoint and credential resolution logic when invoking component load methods with an attacker-supplied credential ID. A remote user can send a specially crafted request using a credential ID from another workspace to disclose sensitive information from third-party resources across workspace boundaries.

The issue affects server-side use of credentials from a different workspace and can return provider metadata such as Google Drive files, Google Sheets spreadsheets, or AWS DynamoDB tables without exposing the raw credential secret.


Affected software

Flowise

How to mitigate CVE-2026-90534

Install security update from vendor's website.

Flowise - update to 3.1.4

External References

Related Security Bulletins