CVE-2026-81818
Deferred Deferred - Pending Action

Authorization Bypass in Flowintel Allows Org Admin to Modify Full Admin Accounts

Vulnerability report for CVE-2026-81818, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: CIRCL

Description

Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API. The existing authorization check correctly prevented an organization administrator from editing users in another organization, but it did not prevent them from editing a full administrator within their own organization. As a result, an org admin could modify that full administrator account, including changing its password. The upstream commit explicitly describes the issue as: β€œOrg admin can change the password of a full admin in the same organization.” The fix adds a higher-privilege boundary check: if user_to_edit.is_admin(): return ... 403 so organization administrators can no longer modify full administrator accounts. Version impacted >=3.3.0

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-09-17
AI Q&A
2026-08-27
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
flowintel flowintel From 3.3.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization flaw in Flowintel's administrative user-edit API. It allows an organization administrator to modify a full administrator account within their own organization, including changing its password. The issue occurs because the existing authorization check prevents editing users in other organizations but fails to block modifications to other admins in the same organization.

Detection Guidance

To detect this vulnerability, check for unauthorized modifications to admin accounts by reviewing logs for API calls to the administrative user-edit endpoint. Look for 403 errors in the logs when org admins attempt to edit full admin accounts within the same organization.

Impact Analysis

An attacker with organization admin privileges could escalate their access by changing the password of a full administrator account. This could grant them higher privileges, allowing them to perform unauthorized actions, access sensitive data, or disrupt system operations within the organization.

Compliance Impact

This vulnerability could lead to unauthorized access or privilege escalation, violating data protection requirements in GDPR and HIPAA. It undermines access control principles, potentially resulting in non-compliance with regulatory mandates for data security and user access management.

Mitigation Strategies

Immediately apply the patch from the provided commit to enforce the higher-privilege boundary check. Ensure no unauthorized admin account modifications have occurred by auditing recent changes to admin credentials and permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81818. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart