CVE-2026-81818
8.6Flowintel · Flowintel
Flowintel contains an authorization flaw in the administrative user-edit API that allows an organization administrator to modify or reset the password of a full administrator account.
Executive summary
An authorization vulnerability in Flowintel allows authenticated organization administrators to escalate privileges by modifying full administrator accounts, posing a severe risk to system integrity.
Vulnerability
The vulnerability is an improper privilege management flaw (CWE-269) located in the administrative user-edit API. It allows an authenticated organization administrator to perform unauthorized actions on a full administrator account within the same organization, specifically enabling password resets.
Business impact
The ability for a lower-privileged organization administrator to compromise a full administrator account represents a total loss of access control. This vulnerability could lead to unauthorized system-wide changes, data exfiltration, or a complete takeover of the management environment. With a CVSS score of 8.6, this flaw is considered high severity due to the potential for significant impact on system confidentiality and integrity.
Remediation
Immediate Action: Organizations should restrict administrative access to trusted personnel and verify if their current Flowintel deployment is within the affected range. While a specific patch version is not explicitly named, administrators must apply the latest security updates provided by the vendor to implement the required privilege boundary checks.
Proactive Monitoring: Review administrative audit logs for suspicious password change events or modifications to high-privilege account attributes. Monitor API logs for unusual patterns of interaction with the user-edit endpoints.
Compensating Controls: Implement strict identity and access management policies and consider limiting the number of users with organization administrator privileges until the software is updated.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the direct impact on administrative account security, this vulnerability presents a significant risk to organizational infrastructure. Security teams should prioritize the identification of all affected Flowintel instances and ensure that the necessary vendor-provided updates are applied as soon as they become available. Failure to remediate this flaw leaves the core administrative management plane exposed to unauthorized modification.
More Flowintel CVEs
Sources
Originally found and disclosed by Jeroen Pinoy, with David Cruciani (remediation developer), per the CVE Program record.