Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-8635: IBM Langflow OSS Privilege Escalation and Command Execution
CVE-2026-8635
Summary
Authenticated users on IBM Langflow OSS can gain superuser access and execute system commands, putting sensitive data at risk. This is a critical issue that requires immediate attention from administrators. To protect your system, update to a secure version of IBM Langflow OSS.
Original title
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full syste...
Original description
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.
nvd CVSS3.1
9.9
Vulnerability type
CWE-94
Code Injection
Published: 17 Jul 2026 · Updated: 18 Jul 2026 · First seen: 17 Jul 2026