Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
6156 articles · 219960 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-9198KEVEXPLOITEDPATCHED
langflow · langflow

Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation

Description

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

Affected Products

VendorProductVersions
langflowlangflow1.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmlangflowcert_advisory90%

References

  • https://www.ibm.com/support/pages/node/7278927(vendor-advisory, patch)

Related News (9 articles)

Tier C
Exploit-DB19d ago
[webapps] Langflow 1.10.0 - RCE
→ No new info (linked only)
Tier C
Rapid7 Blog23d ago
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
→ No new info (linked only)
Tier B
CERT-FR42d ago
Bulletin d'actualité CERTFR-2026-ACT-034 (10 août 2026)
→ No new info (linked only)
Tier D
Heise Security45d ago
Angreifer attackieren IBM Langflow und Apache-Tomcat-Server
→ No new info (linked only)
Tier D
BleepingComputer46d ago
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
→ No new info (linked only)
Tier D
SecurityWeek47d ago
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
→ No new info (linked only)
Tier D
The Hacker News47d ago
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
→ No new info (linked only)
Tier B
BSI Advisories63d ago
[NEU] [hoch] IBM Langflow Desktop OSS: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB65d ago
CVE-2026-9198 | IBM Langflow OSS up to 1.10.0 Code Execution exec os command injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://www.ibm.com/support/pages/node/7278927
CWECWE-94
PublishedJul 17, 2026
Last enriched65d agov2
Tags
os-command-injectioncode-execution-handler
Trending Score11
Source articles9
Independent9
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-9196
Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
HIGHCVE-2026-8470
Langflow is affected by weaknesses in secret handling and sensitive configuration access
HIGHCVE-2026-8478
Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
HIGHCVE-2026-17632
Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
HIGHCVE-2026-9081
Langflow OSS is affected by server-side request forgery in provider validation and API request functionality

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 17, 2026
Added to CISA KEV
Jul 17, 2026
Discovered by ZDM
Jul 17, 2026
Updated: affectedVersions, cweIds, tags
Jul 17, 2026
Actively Exploited
Aug 17, 2026
Exploit Available
Aug 17, 2026
Patch Available
Aug 17, 2026

Version History

v2
Last enriched 65d ago
v2Tier C65d ago

Expanded affected versions to include all releases from 1.0.0 through 1.10.0, added CWE-78 for OS command injection, and added relevant tags identifying the specific vulnerability mechanism.

affectedVersionscweIdstags
via VulDB
v165d ago

Initial creation