External risk intelligence

Flowise Authentication Bypass Via Email Claiming

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-100607

Flowise is a low-code platform for building LLM applications, which is commonly deployed as a web-based application or API service. Because it manages chatflows, credentials, and API keys, and typically requires user authentication to access these features, it is frequently exposed to the network or the internet to enable remote collaboration and integration with other services.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in Flowise, a platform used for building AI applications. The flaw allows unauthorized individuals to gain complete account access by exploiting how the system handles user authentication via email, potentially compromising sensitive information and application functionality.

  • Authentication flaw bypasses user accounts via email.
  • Critical access can be gained to sensitive data.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could compromise user accounts in Flowise by exploiting how it handles email addresses during authentication. By registering a victim's email address with a different single sign-on (SSO) provider or by using a local password, an attacker could gain unauthorized access to all associated data.

  • Requires network access to the application.
  • Attacker claims victim's email address.
  • Complete account access, including sensitive data.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, attackers could authenticate as any existing user by claiming their email at a configured SSO provider, potentially gaining complete account access to chatflows, credentials, and API keys.

  • User accounts and associated data.
  • Email claimed at SSO provider.
  • Complete account compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The critical vulnerability in Flowise affects authentication and could allow unauthorized access to user accounts, chatflows, credentials, and API keys. Application owners or platform teams are likely responsible for managing Flowise deployments. The first practical step is to identify all Flowise instances, confirm their reachability and business criticality, and then determine the accountable owner for remediation planning.

  • Identify Flowise instances; confirm reachability and criticality.
  • Accountable team: Application or platform owners.
  • Plan remediation based on identified exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Flowise?

Flowise is a low-code software platform designed for building and managing Large Language Model (LLM) applications. It provides a visual interface for developers to create complex chatflows, integrate various AI tools, and manage the underlying API keys and credentials required for these automated services.

How does CVE-2026-100607 work?

This vulnerability, classified as Improper Authentication (CWE-287), stems from how the software validates identity. Instead of binding a user to a specific security provider or subject ID, the system relies solely on the email address. This allows an attacker to impersonate any existing user by simply claiming their email address through any supported authentication method.

Do I need to do anything for this to be triggered?

An attacker needs network access to the Flowise instance to initiate the exploit. The vulnerability is not triggered by accidental clicks or standard user behavior; it requires the attacker to actively register or sign in using a victim's email address via an SSO provider or local password mechanism configured on the target system.

Is my Flowise instance at risk?

According to Halo Surface Signal, Flowise is often deployed as a web-based application or API service and is frequently exposed to the network or internet to support remote collaboration. If your instance is internet-facing or accessible to unauthorized network segments, it is more likely to be reachable by an attacker attempting this authentication bypass.

How should I respond to this vulnerability?

Begin by auditing your environment to identify all active Flowise deployments and their respective network reachability. Once you have a clear inventory, coordinate with the accountable application or platform owners to assess the business criticality of each instance and initiate a formal remediation plan to secure user authentication.

References