Authentication Bypass in IBM Langflow OSS Product
CVE-2026-10560

8.2HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 June 2026

What is CVE-2026-10560?

IBM Langflow OSS versions 1.0.0 to 1.9.6 are affected by a missing authentication vulnerability in the /api/v1/build_public_tmp/ endpoints. This vulnerability allows an unauthenticated attacker to exploit the system by reading sensitive build event data or by cancelling jobs using a valid job identifier. The result is both information disclosure and potential denial of service, presenting significant security risks for users of the affected software.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.9.6

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.