Authentication Bypass in IBM Langflow OSS Product
CVE-2026-10560
8.2HIGH
What is CVE-2026-10560?
IBM Langflow OSS versions 1.0.0 to 1.9.6 are affected by a missing authentication vulnerability in the /api/v1/build_public_tmp/ endpoints. This vulnerability allows an unauthenticated attacker to exploit the system by reading sensitive build event data or by cancelling jobs using a valid job identifier. The result is both information disclosure and potential denial of service, presenting significant security risks for users of the affected software.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.9.6