CVE-2026-8635
Authenticated users of IBM Langflow OSS versions 1.0.0 through 1.10.0 can manipulate the database to gain superuser privileges, execute arbitrary system commands, and achieve full system compromise. The vulnerability is rated critical with a CVSS base score of 9.9. No official fix is mentioned in the provided sources.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of IBM Langflow OSS versions 1.0.0 through 1.10.0 who have authenticated access.
Real-world impact
An attacker with legitimate credentials could escalate to superuser, run arbitrary commands on the underlying system, and fully compromise the host running Langflow.
Why this severity
A CVSS score of 9.9 (critical) reflects the combination of low attack complexity, no user interaction, low privileges required, and high impacts to confidentiality, integrity, and availability.
What to do about it
- 01No official fix is specified in the provided data. Monitor IBM Langflow OSS advisories for future patches.
- ›Restrict database access to trusted administrators.
- ›Monitor and audit privileged user activity.
- ›Apply the principle of least privilege for Langflow service accounts.
Remediation guidance is based on general security best practices; no vendor patch or CISA KEV directive is present in the sources.
Timeline
- Jul 17, 2026 · 16d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- ibm.com/support/pages/node/7278925vendor advisory