Improper Authentication in IBM Langflow OSS Affects Multiple Versions
CVE-2026-18891

8.2HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
28 August 2026

What is CVE-2026-18891?

IBM Langflow OSS versions from 1.0.0 to 1.11.1 are susceptible to a vulnerability that allows remote attackers to execute arbitrary flows. This occurs due to improper authentication mechanisms, potentially leading to unauthorized access to sensitive data. Ensuring that your systems are updated and that applicable patches are applied is crucial to mitigate these risks.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.11.1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.