Authorization bypass through user-controlled key in Flowise - #VU146546
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to gain administrative access to another organization\'s workspaces and resources.
The vulnerability exists due to authorization bypass through user-controlled key in organization and workspace membership APIs when processing attacker-supplied organization and workspace identifiers. A remote user can send crafted API requests with another organization\'s IDs to gain administrative access to another organization\'s workspaces and resources.
Exploitation requires a valid authenticated session with management permissions in the attacker\'s own organization and no victim interaction.