PT-2026-60839 · Ibm · Langflow Oss

CVE-2026-9103

·

Published

2026-07-17

·

Updated

2026-09-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Langflow OSS versions 1.0.0 through 1.10.0
Description Improper authentication in the '/api/v1/login/auto login' endpoint allows remote attackers to gain unauthorized administrative access. When the AUTO LOGIN configuration is enabled, which is the default setting, the endpoint issues long-lived superuser bearer tokens without requiring authentication. Furthermore, permissive Cross-Origin Resource Sharing (CORS)—a mechanism that allows restricted resources on a web page to be requested from another domain—may expose these tokens to unintended origins.
Recommendations Disable the AUTO LOGIN configuration for versions 1.0.0 through 1.10.0 to prevent the issuance of unauthenticated superuser tokens.

Fix

DoS

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9103

Affected Products

Langflow Oss