CVE-2026-9103
A security flaw in IBM Langflow OSS allows remote attackers to bypass authentication via a specific login endpoint. This occurs because the system issues long-lived administrative tokens without requiring a password when a certain configuration is enabled.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of IBM Langflow OSS versions 1.0.0 through 1.10.0.
Real-world impact
An attacker could gain full administrative control over the Langflow instance without needing a username or password, potentially allowing them to access sensitive data or modify system settings.
Why this severity
The critical score reflects that the vulnerability can be exploited remotely over a network without any user interaction or authentication, granting full control over the system.
What to do about it
- ›Disable the AUTO_LOGIN configuration if possible
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
NVD description
Timeline
- Jul 17, 2026 · 16d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- ibm.com/support/pages/node/7278926vendor advisory