Junglewise Threat Intelligence

CVE-2026-100608: Flowise authorization bypass in BullMQ admin dashboard

CVE-2026-100608 · Severity: high · CVSS 8.3 · Published 2026-09-26

Vendors: Flowise.

Executive brief

Flowise, an AI workflow and chatbot platform, fails to enforce proper access control on its job queue dashboard when run in queue mode. Any authenticated user—even with minimal permissions—can view sensitive data from other tenants including chat messages, credentials, source code, and system prompts, and can perform destructive actions like deleting or retrying jobs across the entire platform.

Technical details

The /admin/queues endpoint uses only JWT authentication via verifyTokenForBullMQDashboard middleware but performs no role, permission, or workspace/organization scoping checks. Any authenticated user gains access to the full Bull-Board UI and all queued job payloads across all instances, including incomingInput, credential IDs, chatflow.flowData with custom JavaScript code, and originating tenant identifiers. The endpoint lies outside the /api/v1/* protected tree and write actions (retry, remove, promote, clean) are cross-tenant enabled.

Affected products

  • Flowise Flowise through 3.1.4

Timeline

  • 2026-09-26: disclosed
  • 2026-01-08: other: Incomplete fix added authentication but not authorization (commit 1bfa7a1c)

References