Authenticated Access Vulnerability in IBM Langflow OSS Tools
CVE-2026-12763

4.2MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 September 2026

What is CVE-2026-12763?

The vulnerability affects IBM Langflow OSS versions from 1.0.0 to 1.11.5, posing a risk where an authenticated attacker can exploit improper cache key isolation in the MCP Tools component. This flaw could potentially allow the attacker to access another user's MCP server context, leading to unauthorized disclosure of sensitive information. Immediate attention to patching and securing affected versions is recommended to mitigate risks.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.11.5

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.