Description
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.
Published: 2026-09-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper authentication leading to unauthorized password changes
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper authentication flaw in the password reset endpoint of IBM Langflow OSS. An attacker who can craft a reset request can change a target account's password without providing the current or any verification credentials. This allows the attacker to take control of the affected account, potentially gaining full access to the application data and any integrations the account may have. The weakness is identified as CWE-287.

Affected Systems

IBM Langflow OSS versions from 1.0.0 through 1.10.2 are vulnerable. The latest unpatched release listed is 1.10.2. Upgrading to version 1.10.3 or later eliminates the flaw.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. EPSS is not available, so the likelihood of exploitation is uncertain. The issue is not listed in the CISA KEV catalog. The attack requires only the ability to send a password reset request to the target application, without requiring privileged credentials or complex configurations, making it potentially accessible to remote attackers.

Generated by OpenCVE AI on September 15, 2026 at 12:03 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.3 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Deploy the official patch by upgrading IBM Langflow OSS to 1.10.3.
  • If the upgrade cannot be performed immediately, restrict access to the password reset functionality to trusted IP ranges or enforce multi‑factor authentication for reset requests.
  • Monitor account activity and password reset logs for suspicious changes.
  • Inform users of the vulnerability and advise them to change passwords promptly.

Generated by OpenCVE AI on September 15, 2026 at 12:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.
Title Langflow is affected by improper authentication due to missing password verification in the password reset endpoint
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T20:13:31.799Z

Reserved: 2026-07-27T21:07:31.398Z

Link: CVE-2026-17628

cve-icon Vulnrichment

Updated: 2026-09-14T20:13:24.946Z

cve-icon NVD

Status : Received

Published: 2026-09-14T20:16:42.140

Modified: 2026-09-14T21:17:04.100

Link: CVE-2026-17628

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T12:15:08Z

Weaknesses