CVE-2026-30823

HIGH

Flowise < 3.0.13 - Unauthenticated IDOR and Account Takeover via SSO Configuration

Title source: llm
STIX 2.1

Description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0045
EPSS Percentile 35.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-862 CWE-639
Status published
Products (2)
flowiseai/flowise < 3.0.13
npm/flowise 0 - 3.0.13npm
Published Mar 07, 2026
Tracked Since Mar 07, 2026