CVE-2026-8505
A flaw in the authentication logic of IBM Langflow OSS allows unauthorized users to trigger any workflow. This occurs because the system bypasses API key validation when the default configuration is used.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of IBM Langflow OSS versions 1.0.0 through 1.10.0.
Real-world impact
An attacker who knows a specific flow's unique ID can execute it remotely without needing credentials, which could lead to full remote code execution on the system.
Why this severity
The critical score reflects that the vulnerability can be exploited remotely over the network without any user interaction or authentication, potentially compromising the entire system.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
NVD description
Timeline
- Jul 17, 2026 · 16d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- ibm.com/support/pages/node/7278921vendor advisory