Skip to main content
Vulnerability Database/CVE-2026-100606

CVE-2026-100606: Flowise SSO Authentication Bypass Vulnerability

CVE-2026-100606 is an authentication bypass flaw in Flowise Enterprise SSO mode that lets attackers hijack pending user invitations without possessing invitation tokens. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-100606 Overview

Flowise through version 3.1.4 contains an authentication bypass [CWE-287] in the Single Sign-On (SSO) login path when deployed in Enterprise or platform mode with SSO enabled. The flaw allows any attacker who can authenticate at a configured SSO provider using a pending invitee's email address to take over the invitation and gain the invited user's organization access. No emailed invitation token is required. At the time of advisory publication, no patched version was available.

Critical Impact

Attackers obtain full access to an invited user's organization membership for up to 24 hours per invitation, without possessing the single-use invitation token delivered by email.

Affected Products

  • Flowise versions through 3.1.4
  • Flowise Enterprise mode with SSO enabled
  • Flowise platform mode with SSO enabled

Discovery Timeline

  • 2026-09-26 - CVE-2026-100606 published to NVD
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-100606

Vulnerability Analysis

The vulnerability resides in the SSO callback handling logic within SSOBase.ts at lines 80-94. When an SSO callback arrives containing an email claim matching an existing user whose status is INVITED, the verifyAndLogin function retrieves the full user record from the database. This record includes the server-stored single-use invitation tempToken intended to be delivered to the invitee by email.

The code then passes this server-side token into AccountService.register() as if it were caller-supplied. The register handler validates the token against the database, matches the email, and checks expiry. All three checks pass trivially because the server is comparing its own token to itself. The account and its organization membership are then flipped to ACTIVE.

Root Cause

The root cause is a trust boundary violation. The verifyAndLogin function treats data read from the server's own database as if it were an authenticated caller input. The invitation token design assumes the token travels out-of-band via email, serving as proof of invitation ownership. By substituting the stored token for a user-supplied one, the SSO path removes the only authorization check that bound the invitation to the email recipient.

Attack Vector

An attacker identifies an invited email address belonging to a target Flowise organization. The attacker then authenticates at any SSO provider configured on the target instance using that email as the claim. The SSO callback triggers the vulnerable code path, which activates the pending invitation and binds the attacker's SSO identity to the invited account. The attacker gains the organization permissions assigned to the invitee. The attack window remains open for the invitation validity period, which defaults to 24 hours.

See the VulnCheck Advisory on Authentication Bypass for full technical details.

Detection Methods for CVE-2026-100606

Indicators of Compromise

  • SSO login events where a user transitioned from INVITED to ACTIVE status within the same session as the first SSO callback for that email
  • Successful SSO authentications originating from identity provider accounts that do not match the organization's expected directory for the invited email
  • Organization membership activation events without a corresponding GET of the invitation acceptance URL containing the tempToken parameter

Detection Strategies

  • Correlate Flowise application logs for verifyAndLogin invocations against pending invitations and compare the SSO provider identity to prior known-good identities for that email domain
  • Alert on any AccountService.register() success where the token in the request body was absent or did not match the token delivered in the invitation email
  • Review audit trails for new organization members added within 24 hours of an invitation being issued, cross-referencing the SSO provider used

Monitoring Recommendations

  • Enable verbose authentication logging on all configured SSO providers and forward events to a central SIEM for correlation
  • Monitor for brute-force or enumeration against the SSO callback endpoint using known or guessed internal email addresses
  • Track invitation issuance and acceptance as paired events; investigate any acceptance that lacks a matching email-delivery confirmation

How to Mitigate CVE-2026-100606

Immediate Actions Required

  • Disable SSO on Flowise Enterprise or platform mode deployments until a patched release is available, or restrict the SSO provider to a tenant that excludes external users
  • Revoke all outstanding pending invitations and reissue them only after mitigations are in place
  • Audit organization membership for any account activated via SSO since SSO was enabled, prioritizing accounts activated near invitation issuance

Patch Information

At the time of advisory publication, no patched version of Flowise was available. Monitor the Flowise GitHub Security Advisory GHSA-vf3j-89vf-r697 for release information and apply updates as soon as a fixed version ships.

Workarounds

  • Reduce the default invitation validity window from 24 hours to the shortest operationally acceptable period to limit the attack window
  • Restrict configured SSO providers to identity domains that are fully controlled by the organization, preventing external attackers from presenting arbitrary email claims
  • Require administrators to manually activate invited users rather than relying on self-service SSO activation during the exposure window
bash
# Example: temporarily disable SSO in Flowise environment configuration
# Remove or comment out SSO-related environment variables before restart
# SSO_PROVIDER=azure
# SSO_CLIENT_ID=...
# SSO_CLIENT_SECRET=...
unset SSO_PROVIDER SSO_CLIENT_ID SSO_CLIENT_SECRET
pm2 restart flowise

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.