CVE-2026-13446
IBM Langflow OSS versions 1.0.0 through 1.10.1 contain hard-coded credentials that could allow attackers to authenticate, communicate with external components, or decrypt internal data. The vulnerability is rated critical with a CVSS score of 9.8. No known exploitation or public exploit is reported, and no official fix is provided in the sources.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of IBM Langflow OSS versions 1.0.0 to 1.10.1
Real-world impact
An attacker could exploit the hard-coded credentials to gain unauthorized access, intercept or alter communications, or decrypt sensitive data stored by the application.
Why this severity
The CVSS base score of 9.8 (Critical) reflects that the vulnerability is network‑reachable, requires low attack complexity, needs no privileges or user interaction, and can lead to high impacts on confidentiality, integrity, and availability.
What to do about it
- 01No official fix is mentioned in the provided sources.
- ›Monitor for unofficial patches or workarounds from the vendor.
- ›Restrict network access to the Langflow service to trusted hosts only.
- ›Review and rotate any credentials that may be embedded in the application if possible.
Remediation guidance is based solely on the absence of an official fix in the supplied data; no vendor patch or CISA KEV directive is available.
Timeline
- Jul 17, 2026 · 16d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- ibm.com/support/pages/node/7279991vendor advisory