PT-2026-60834 · Ibm · Langflow Oss

CVE-2026-9202

·

Published

2026-07-17

·

Updated

2026-07-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Langflow OSS versions 1.0.0 through 1.10.0
Description Improper authentication and access control in the user registration and account provisioning logic allow unauthenticated attackers to create unlimited user accounts. This occurs when attackers access the signup and user-creation endpoints. If the deployment option NEW USER IS ACTIVE is set to true, these newly created accounts are immediately active, allowing attackers to authenticate and access endpoints capable of Remote Code Execution (RCE), which is the ability to execute arbitrary commands on a remote machine. This bypasses the need for AUTO LOGIN and can lead to a full takeover of the host and data.
Recommendations Update IBM Langflow OSS to version 1.10.1 or later. Disable the NEW USER IS ACTIVE option and restrict registration.

Fix

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9202

Affected Products

Langflow Oss