#VU125529 Authorization bypass through user-controlled key in Flowise - CVE-2026-30823
Published: April 9, 2026
Flowise
FlowiseAI
Description
The vulnerability allows a remote user to take over accounts and bypass enterprise feature restrictions.
The vulnerability exists due to authorization bypass through a user-controlled key in the PUT /api/v1/loginmethod endpoint when handling authenticated requests that supply an organizationId in the JSON body. A remote user can send a specially crafted request with a target organizationId to take over accounts and bypass enterprise feature restrictions.
The issue can be exploited by overwriting another organization's SSO configuration, including provider credentials, and does not require user interaction.