Vulnary
← back to the feed
Critical· 9.8

CVE-2026-13446

IBM Langflow OSS versions 1.0.0 through 1.10.1 contain hard-coded credentials that could allow attackers to authenticate, communicate with external components, or decrypt internal data. The vulnerability is rated critical with a CVSS score of 9.8. No known exploitation or public exploit is reported, and no official fix is provided in the sources.

publishedJul 17, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
13th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 1, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Users of IBM Langflow OSS versions 1.0.0 to 1.10.1

02

Real-world impact

An attacker could exploit the hard-coded credentials to gain unauthorized access, intercept or alter communications, or decrypt sensitive data stored by the application.

03

Why this severity

The CVSS base score of 9.8 (Critical) reflects that the vulnerability is network‑reachable, requires low attack complexity, needs no privileges or user interaction, and can lead to high impacts on confidentiality, integrity, and availability.

04

What to do about it

no official fix yet
recommended steps
  1. 01No official fix is mentioned in the provided sources.
interim mitigations
  • Monitor for unofficial patches or workarounds from the vendor.
  • Restrict network access to the Langflow service to trusted hosts only.
  • Review and rotate any credentials that may be embedded in the application if possible.

Remediation guidance is based solely on the absence of an official fix in the supplied data; no vendor patch or CISA KEV directive is available.

05

Timeline

  1. Jul 17, 2026 · 16d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 23, 2026 · 10d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2026-13446: IBM Langflow OSS versions 1.0.0 through 1.10.1 contain hard-coded cred · Vulnary