CVE-2026-9202
IBM Langflow OSS versions 1.0.0 through 1.10.0 allow unauthenticated attackers to create unlimited user accounts. When the deployment option NEW_USER_IS_ACTIVE is set to true, those accounts become active immediately and can be used to reach remote code execution endpoints without needing auto-login. The vulnerability is rated critical with a CVSS base score of 9.8.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
IBM Langflow OSS 1.0.0 through 1.10.0
Real-world impact
Attackers can create accounts that grant them access to RCE endpoints, leading to full compromise of the service.
Why this severity
CVSS 3.1 score of 9.8 (Critical) reflects network‑based attack, low complexity, no privileges or user interaction required, and high impact on confidentiality, integrity, and availability.
What to do about it
- 01No official fix is mentioned in the provided sources; monitor IBM Langflow OSS for future patches.
- ›Consider disabling the NEW_USER_IS_ACTIVE deployment option if it is not required, or restrict account creation to trusted networks.
Remediation guidance is derived solely from the given data; no vendor patch or CISA KEV action is specified.
Timeline
- Jul 17, 2026 · 16d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 9d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- ibm.com/support/pages/node/7278929vendor advisory