Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper access control.
Published: 2026-10-06
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.12.2 contain an improper access control flaw (CWE-284) that enables a remote authenticated attacker to retrieve sensitive information. The vulnerability requires the attacker to be authenticated to the application, after which they can read privileged data that should be restricted to authorized users. This weakness can lead to the compromise of confidential business data, user personal information, or other protected resources accessible within the Langflow environment.

Affected Systems

The affected product is IBM Langflow OSS. All releases from version 1.0.0 up to but not including 1.12.3 are vulnerable. Users deploying any of these versions should verify their installation versions and plan to upgrade.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score is not available, suggesting limited public exploitation data. The vulnerability is not listed in CISA’s KEV catalog, implying it is not a widely known exploited vulnerability. A remote authenticated attacker—potentially one who has compromised valid credentials or gained access via weak authentication—can exploit the flaw to obtain sensitive data. The attack vector is remote; local restrictions on the host are insufficient to mitigate the exposed access control issue.

Generated by OpenCVE AI on October 7, 2026 at 01:40 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.12.3. https://pypi.org/project/langflow/#description


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.12.3 or later to fix the improper access control flaw.
  • If an immediate upgrade is not possible, restrict or remove privileged user accounts, enforce least‑privilege access controls, and ensure all authentication mechanisms are strong and monitored.
  • Implement logging and monitoring of sensitive data access to detect unauthorized attempts and investigate anomalous activity promptly.

Generated by OpenCVE AI on October 7, 2026 at 01:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper access control.
Title Langflow OSS is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-06T23:58:47.055Z

Reserved: 2026-09-28T14:06:06.300Z

Link: CVE-2026-101329

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T01:16:32.837

Modified: 2026-10-07T01:16:32.837

Link: CVE-2026-101329

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:45:08Z

Weaknesses