Vulnary
← back to the feed
Critical· 9.8

CVE-2026-9202

IBM Langflow OSS versions 1.0.0 through 1.10.0 allow unauthenticated attackers to create unlimited user accounts. When the deployment option NEW_USER_IS_ACTIVE is set to true, those accounts become active immediately and can be used to reach remote code execution endpoints without needing auto-login. The vulnerability is rated critical with a CVSS base score of 9.8.

publishedJul 17, 2026
last modifiedJul 24, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
20th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 1, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

IBM Langflow OSS 1.0.0 through 1.10.0

02

Real-world impact

Attackers can create accounts that grant them access to RCE endpoints, leading to full compromise of the service.

03

Why this severity

CVSS 3.1 score of 9.8 (Critical) reflects network‑based attack, low complexity, no privileges or user interaction required, and high impact on confidentiality, integrity, and availability.

04

What to do about it

no official fix yet
recommended steps
  1. 01No official fix is mentioned in the provided sources; monitor IBM Langflow OSS for future patches.
interim mitigations
  • Consider disabling the NEW_USER_IS_ACTIVE deployment option if it is not required, or restrict account creation to trusted networks.

Remediation guidance is derived solely from the given data; no vendor patch or CISA KEV action is specified.

05

Timeline

  1. Jul 17, 2026 · 16d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 24, 2026 · 9d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →