Insecure Direct Object Reference in Langflow Tool by Langflow AI
CVE-2026-55255

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
23 June 2026

Badges

📈 Score: 305💰 Ransomware👾 Exploit Exists🟣 EPSS 29%🦅 CISA Reported📰 News Worthy

What is CVE-2026-55255?

CVE-2026-55255 is a security vulnerability found in the Langflow tool, which is designed for creating and deploying AI-powered agents and workflows. Specifically, it represents an Insecure Direct Object Reference (IDOR) issue that exists in the /api/v1/responses endpoint. Prior to release version 1.9.1, this vulnerability allowed an authenticated user to access and manipulate the workflow flows of other users by specifying their flow ID in a request. This improper validation can lead to unauthorized exposure of data and improper action on users’ workflows, ultimately compromising the confidentiality and integrity of application workflows. This could severely impact an organization's operational security and user trust, particularly if sensitive data is involved in the workflows.

Potential impact of CVE-2026-55255

  1. Unauthorized Access to User Data: The vulnerability enables attackers to manipulate workflows that belong to other users, potentially leading to unauthorized access to sensitive and confidential information, which can have severe privacy implications.

  2. Workflow Manipulation: Exploiting this vulnerability allows attackers to execute unauthorized operations on workflows, leading to disruptions in business processes, potential data loss, and operational downtime, which can affect productivity and service delivery.

  3. Reputation Damage: Organizations affected by such vulnerabilities may suffer reputational harm if customers’ data is compromised or misused, which could lead to loss of customer trust and business opportunities.

CISA has reported CVE-2026-55255

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-55255 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

langflow < 1.9.1

News Articles

Week in review: Accenture data breach, great open-source cybersecurity tools - Help Net Security

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Securing the inbox: Where identity, brand and security

CISA orders feds to prioritize patching Langflow auth bypass flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents.

References

EPSS Score

29% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 💰

    Used in Ransomware

  • 📰

    First article discovered by BleepingComputer

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

.