PT-2026-60879 · Ibm · Langflow Oss

CVE-2026-13446

·

Published

2026-07-17

·

Updated

2026-07-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Langflow OSS versions 1.0.0 through 1.10.1
Description The software contains hard-coded credentials, such as passwords or cryptographic keys. These credentials are used for inbound authentication, outbound communication with external components, or the encryption of internal data, which may lead to unauthorized access and data compromise.
Recommendations Isolate affected systems immediately. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13446

Affected Products

Langflow Oss