Vulnerability Description
Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash and temporary tokens. Attackers can query the endpoint with any user ID to obtain the owner's credential hash for offline cracking, enabling account takeover of the highest-privileged account.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flowiseai | Flowise | < 3.1.4 |
Related Weaknesses (CWE)
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-fhxm-xxcx-g6x3ExploitVendor Advisory
- https://www.vulncheck.com/advisories/flowise-before-3.1.4-broken-access-control-Third Party Advisory
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-fhxm-xxcx-g6x3ExploitVendor Advisory
FAQ
What is CVE-2026-90533?
CVE-2026-90533 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user rec...
How severe is CVE-2026-90533?
CVE-2026-90533 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-90533?
Check the references section above for vendor advisories and patch information. Affected products include: Flowiseai Flowise.