External risk intelligence

Flowise Authentication Bypass via SSO Email Match

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-100606

Flowise is a web-based platform for building AI workflows. The vulnerability exists in the SSO login path, a core component designed for user authentication. Such platforms are commonly deployed as internet-facing web applications or management portals to facilitate remote team access and integration, making the login surface readily accessible over the network.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details an authentication bypass vulnerability in Flowise, specifically affecting systems using Single Sign-On (SSO) with an "INVITED" user status. An attacker could potentially hijack an invitation by using an invited user's email address with a configured SSO provider, gaining unauthorized access to the invited user's account and organizational membership.

  • Bypass allows unauthorized account access.
  • It impacts how invited users gain access.
  • Confirm relevance and exposure of invited accounts.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authentication by exploiting a vulnerability in the single sign-on (SSO) login process of Flowise. If an attacker can authenticate to a configured SSO provider using an email address that matches a user who has been invited but has not yet accepted, they can hijack that invitation. This allows them to gain the invited user's access to the organization without possessing the original invitation token.

  • Attacker needs SSO access and an invited user's email.
  • Attacker triggers by completing SSO with invited user's email.
  • Risk of unauthorized access and control of accounts.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to gain unauthorized access to an organization's resources. If an attacker can authenticate with any configured SSO provider using an email address that matches a pending invitation, they could take over that invitation and gain the invited user's access. This is possible for as long as the invitation remains valid, typically 24 hours.

  • Invited user accounts and organization access.
  • Authenticating with a pending invitee's email.
  • Unauthorized active account access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical authentication bypass vulnerability in Flowise impacts organizations using enterprise or platform mode with SSO enabled. Responsibility likely falls to platform or application owners to identify all instances, confirm business criticality and network reachability, and then coordinate with security and vendor management teams for remediation.

  • Owner: Platform or application owners.
  • Verify: All Flowise instances and SSO configurations.
  • Action: Plan remediation, coordinate with vendor.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Flowise?

Flowise is a web-based platform designed for building and managing AI workflows. It is often deployed as a central portal for team collaboration, allowing users to integrate various AI models and tools into automated processes. Because it manages organizational workflows, it frequently functions as an internet-facing application to support remote access and integration requirements.

What does CVE-2026-100606 mean for security?

This CVE describes an authentication bypass weakness, classified as CWE-287 (Improper Authentication). In affected versions of Flowise, the system incorrectly handles user records during the Single Sign-On (SSO) login process. When an SSO callback occurs for a user with an 'INVITED' status, the application inadvertently allows the login to proceed using the server's internal invitation token instead of verifying a unique, user-provided token.

How is this authentication bypass triggered?

The vulnerability occurs when an attacker authenticates via a configured SSO provider using an email address that matches an existing, pending invitation in Flowise. The system erroneously completes the registration process and activates the account membership automatically. If you are not using SSO, or if the target email address has no pending invitation, this specific bypass path is not applicable.

Is my Flowise instance at risk?

According to Halo Surface Signal, this vulnerability is most relevant for instances deployed as internet-facing web applications. Since the SSO login path is a core component often exposed to facilitate remote team access, any instance with SSO enabled is considered a high-priority area for review. Internal-only instances still face risks if an attacker gains access to your network or SSO provider.

What are the first steps for securing Flowise?

Identify all active Flowise instances and confirm whether they are running in enterprise or platform mode with SSO enabled. Since no patch is currently available, review your organizational account invitation processes and minimize the number of pending 'INVITED' user accounts. Coordinate with your security and platform teams to monitor for unauthorized account activity until a vendor-supplied update is released.

References