Junglewise Threat Intelligence

CVE-2026-30823: Flowise IDOR in SSO configuration API endpoint

CVE-2026-30823 · Severity: low · CVSS 3 · Published 2026-03-06

Technologies: flowise (npm), FlowiseAI Flowise. Vendors: npm, FlowiseAI.

Executive brief

Flowise, a platform for building and managing conversational workflows, contains an authorization flaw in its SSO (single sign-on) configuration API. Any user with a free account can modify another organization's login settings by simply knowing the target organization ID, allowing attackers to hijack employee logins or unlock premium features without payment.

Technical details

The vulnerability is an Insecure Direct Object Reference (IDOR) combined with missing authorization checks in the PUT /api/v1/loginmethod endpoint. While the endpoint requires authentication (low-privileged JWT token), it accepts an organizationId parameter in the request body and directly updates the database without verifying that the authenticated user belongs to or has administrative rights over that organization. An attacker with any valid account (including free tier) can supply a different organizationId and modify OAuth provider credentials (Google, Azure, Okta) for victim organizations, enabling account takeover by redirecting authentication to attacker-controlled applications or enabling restricted enterprise features. The fix is available in version 3.0.13.

Affected products

  • FlowiseAI Flowise <=3.0.12

Timeline

  • 2026-03-06: disclosed
  • 2026-03-06: patched: Fix released in version 3.0.13

References

Related threats