Authorization Bypass Vulnerability in IBM Langflow OSS Product
CVE-2026-19298
8.8HIGH
What is CVE-2026-19298?
IBM Langflow OSS versions 1.0.0 through 1.11.2 are susceptible to an authorization bypass that may enable a remote authenticated attacker to execute arbitrary code during the flow build process. This vulnerability poses risks that necessitate immediate attention from users of affected versions to mitigate potential exploits.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.11.2