CVE-2026-81818

8.6

Flowintel · Flowintel

Flowintel contains an authorization flaw in the administrative user-edit API that allows an organization administrator to modify or reset the password of a full administrator account.

Executive summary

An authorization vulnerability in Flowintel allows authenticated organization administrators to escalate privileges by modifying full administrator accounts, posing a severe risk to system integrity.

Vulnerability

The vulnerability is an improper privilege management flaw (CWE-269) located in the administrative user-edit API. It allows an authenticated organization administrator to perform unauthorized actions on a full administrator account within the same organization, specifically enabling password resets.

Business impact

The ability for a lower-privileged organization administrator to compromise a full administrator account represents a total loss of access control. This vulnerability could lead to unauthorized system-wide changes, data exfiltration, or a complete takeover of the management environment. With a CVSS score of 8.6, this flaw is considered high severity due to the potential for significant impact on system confidentiality and integrity.

Remediation

Immediate Action: Organizations should restrict administrative access to trusted personnel and verify if their current Flowintel deployment is within the affected range. While a specific patch version is not explicitly named, administrators must apply the latest security updates provided by the vendor to implement the required privilege boundary checks.

Proactive Monitoring: Review administrative audit logs for suspicious password change events or modifications to high-privilege account attributes. Monitor API logs for unusual patterns of interaction with the user-edit endpoints.

Compensating Controls: Implement strict identity and access management policies and consider limiting the number of users with organization administrator privileges until the software is updated.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the direct impact on administrative account security, this vulnerability presents a significant risk to organizational infrastructure. Security teams should prioritize the identification of all affected Flowintel instances and ensure that the necessary vendor-provided updates are applied as soon as they become available. Failure to remediate this flaw leaves the core administrative management plane exposed to unauthorized modification.

More Flowintel CVEs

Sources

Originally found and disclosed by Jeroen Pinoy, with David Cruciani (remediation developer), per the CVE Program record.