Junglewise Threat Intelligence

CVE-2026-50173: Flow-Like privilege escalation in Azure invoke presign endpoint

CVE-2026-50173 · Severity: info · CVSS 6.5 · Published 2026-08-19

Executive brief

Flow-Like is a platform for building workflow automation applications. In self-hosted deployments using Azure Blob Storage, a user with workflow execution permissions but no file access rights can exploit an API endpoint to obtain credentials that allow direct read, write, and delete access to application data. This bypasses the application's intended permission model and allows an authenticated insider to corrupt or delete app content and workflow data.

Technical details

The vulnerability is a permission bypass in the GET /api/v1/apps/{app_id}/invoke/presign endpoint. The route correctly gates access to ExecuteEvents permission, but then implements an incomplete permission check for file operations. When a caller has ExecuteEvents but lacks both ReadFiles and WriteFiles permissions, the code defaults to CredentialsAccess::InvokeNone. However, the Azure credential provider incorrectly issues a full SAS token (sp=rwdl) for the app content prefix (apps/{app_id}), granting read, write, delete, and list permissions. This allows the low-privilege user to directly manipulate blobs in Azure storage, bypassing the normal presign routes that enforce WriteFiles checks. The vulnerability only affects self-hosted deployments using Azure Blob Storage; AWS-backed deployments (Flow-Like Studio and hosted Web App) are unaffected because the AWS InvokeNone policy correctly restricts access to temporary and per-user prefixes. Authentication is required, and the attacker must already be an app member with ExecuteEvents permission.

Affected products

  • Rheosoph Flow-Like before 1.0.4

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: patched: version 1.0.4 released

References