Improper Authorization in IBM Langflow OSS Affects User Data Access
CVE-2026-19294
6.4MEDIUM
What is CVE-2026-19294?
IBM Langflow OSS versions 1.0.0 to 1.11.1 contain a vulnerability that permits a remote authenticated attacker to execute actions and read any user's private flows. This flaw arises from inadequate authorization checks within the application, exposing sensitive user data to unauthorized access. Users of affected versions are strongly urged to review the advisory and apply the recommended patches to secure their systems.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.11.1