PT-2026-60834 · Ibm · Langflow Oss
CVE-2026-9202
·
Published
2026-07-17
·
Updated
2026-07-18
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Langflow OSS versions 1.0.0 through 1.10.0
Description
Improper authentication and access control in the user registration and account provisioning logic allow unauthenticated attackers to create unlimited user accounts. This occurs when attackers access the signup and user-creation endpoints. If the deployment option
NEW USER IS ACTIVE is set to true, these newly created accounts are immediately active, allowing attackers to authenticate and access endpoints capable of Remote Code Execution (RCE), which is the ability to execute arbitrary commands on a remote machine. This bypasses the need for AUTO LOGIN and can lead to a full takeover of the host and data.Recommendations
Update IBM Langflow OSS to version 1.10.1 or later.
Disable the
NEW USER IS ACTIVE option and restrict registration.Fix
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow Oss