Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-19297: IBM Langflow OSS: Unauthorized Login Attempts

CVE-2026-19297 · published 1 month ago
Summary

IBM Langflow OSS has a security issue that allows attackers to try many login combinations without being blocked. This could let an attacker guess a user's password and gain access to their account. To stay safe, update IBM Langflow OSS to the latest version.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm langflow oss <= 1.9.6
Original advisory text
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.
References
Severity
9.1 Critical
CVSS 3.1: 9.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-307Improper Restriction of Excessive Authentication Attempts
Timeline
Published13 Aug 2026
Updated25 Sep 2026
First seen13 Aug 2026
Sources
CVE-2026-19297 · MITRE
Track software like this
Free during beta