Description
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.
Published: 2026-09-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper authentication leading to unauthorized password changes
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper authentication flaw in the password reset endpoint of IBM Langflow OSS. A remote authenticated attacker, who has access to an account, can change that account's password without providing the current or any additional verification credentials. This allows the attacker to take control of the affected account, potentially gaining full access to the application data and any integrations the account may have. The weakness is identified as CWE-287.

Affected Systems

IBM Langflow OSS versions from 1.0.0 through 1.10.2 are vulnerable. The latest unpatched release listed is 1.10.2. Upgrading to version 1.10.3 or later eliminates the flaw.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score is below 1%, indicating a very low likelihood of exploitation. The issue is not listed in the CISA KEV catalog. The attack requires that the attacker be authenticated to the target application and able to send a password reset request, allowing the attacker to change the password of an account they have already logged into. This makes the vulnerability accessible to remote attackers with valid credentials.

Generated by OpenCVE AI on September 20, 2026 at 23:23 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.3 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Deploy the official patch by upgrading IBM Langflow OSS to 1.10.3.
  • If the upgrade cannot be performed immediately, restrict access to the password reset functionality to trusted IP ranges or enforce multi‑factor authentication for reset requests.
  • Monitor account activity and password reset logs for suspicious changes.
  • Inform users of the vulnerability and advise them to change passwords promptly.

Generated by OpenCVE AI on September 20, 2026 at 23:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.
Title Langflow is affected by improper authentication due to missing password verification in the password reset endpoint
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T20:13:31.799Z

Reserved: 2026-07-27T21:07:31.398Z

Link: CVE-2026-17628

cve-icon Vulnrichment

Updated: 2026-09-14T20:13:24.946Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:42.140

Modified: 2026-09-16T19:22:22.797

Link: CVE-2026-17628

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:30:07Z

Weaknesses