Description
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
Published: 2026-08-28
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Execution and Data Access
Action: Immediate Patch
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a flaw that allows a remote attacker to bypass authentication controls, enabling the execution of arbitrary flows and the retrieval of sensitive information. The vulnerability stems from improper authentication handling and is related to CWE‑287. This could lead to unauthorized code execution or data exposure within the application.

Affected Systems

The impacted product is IBM Langflow OSS. Versions affected range from 1.0.0 up to and including 1.11.1. All installations of these releases are vulnerable until patched to 1.11.2.

Risk and Exploitability

With a CVSS score of 8.2 the vulnerability is considered high risk. The EPSS metric is not available, so the exploitation probability cannot be quantified, and it is not listed in the CISA KEV catalog. However, the flaw can be exploited remotely without authentication, and an attacker only needs access to the web interface to trigger unsupported flow execution. Because the attack vector is external, organizations should treat it with high urgency.

Generated by OpenCVE AI on August 28, 2026 at 23:24 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.2 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.11.2 or later.
  • If an upgrade is not immediately feasible, restrict external access to the Langflow web interface and monitor for unauthorized flow execution attempts.
  • Ensure that authentication and authorization controls are correctly enforced, such as by validating user sessions before allowing flow execution.

Generated by OpenCVE AI on August 28, 2026 at 23:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Langflow
Langflow langflow
CPEs cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Vendors & Products Langflow
Langflow langflow

Mon, 31 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
Title Langflow is affected by multiple authentication bypass, path traversal, authorization, and server-side request forgery vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Ibm Langflow Oss
Langflow Langflow
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-31T13:52:41.780Z

Reserved: 2026-08-04T19:48:56.798Z

Link: CVE-2026-18891

cve-icon Vulnrichment

Updated: 2026-08-31T13:52:38.816Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-28T22:16:46.990

Modified: 2026-08-31T21:53:54.967

Link: CVE-2026-18891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:30:17Z

Weaknesses