Vulnary
← back to the feed
Critical· 9.9

CVE-2026-8635

Authenticated users of IBM Langflow OSS versions 1.0.0 through 1.10.0 can manipulate the database to gain superuser privileges, execute arbitrary system commands, and achieve full system compromise. The vulnerability is rated critical with a CVSS base score of 9.9. No official fix is mentioned in the provided sources.

publishedJul 17, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.9
critical · how bad it is
exploitation · epss
<1%
22th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 1, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Users of IBM Langflow OSS versions 1.0.0 through 1.10.0 who have authenticated access.

02

Real-world impact

An attacker with legitimate credentials could escalate to superuser, run arbitrary commands on the underlying system, and fully compromise the host running Langflow.

03

Why this severity

A CVSS score of 9.9 (critical) reflects the combination of low attack complexity, no user interaction, low privileges required, and high impacts to confidentiality, integrity, and availability.

04

What to do about it

no official fix yet
recommended steps
  1. 01No official fix is specified in the provided data. Monitor IBM Langflow OSS advisories for future patches.
interim mitigations
  • Restrict database access to trusted administrators.
  • Monitor and audit privileged user activity.
  • Apply the principle of least privilege for Langflow service accounts.

Remediation guidance is based on general security best practices; no vendor patch or CISA KEV directive is present in the sources.

05

Timeline

  1. Jul 17, 2026 · 16d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 23, 2026 · 10d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredLow
User interactionNone needed
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →