Improper Authorization in IBM Langflow OSS Affects User Data Access
CVE-2026-19294

6.4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
28 August 2026

What is CVE-2026-19294?

IBM Langflow OSS versions 1.0.0 to 1.11.1 contain a vulnerability that permits a remote authenticated attacker to execute actions and read any user's private flows. This flaw arises from inadequate authorization checks within the application, exposing sensitive user data to unauthorized access. Users of affected versions are strongly urged to review the advisory and apply the recommended patches to secure their systems.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.11.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.