Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-9103: IBM Langflow: Unauthenticated Access to Administrative Features
CVE-2026-9103
CVE-2026-9103
Summary
IBM Langflow OSS versions 1.0.0 to 1.10.0 have a security issue that allows unauthorized access to administrative features. This can happen if a network attacker uses a feature called auto-login. To protect yourself, update IBM Langflow to the latest version and review your configuration settings, especially those related to auto-login and cross-origin resource sharing.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | langflow oss | <= 1.10.0 |
Original title
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-liv...
Original description
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unintended origins, increasing the risk of unauthorized access.
mitre CVSS3.1
9.8
Vulnerability type
CWE-306
Missing Authentication for Critical Function
- https://www.ibm.com/support/pages/node/7278926 vendor-advisory patch
Published: 17 Jul 2026 · Updated: 20 Jul 2026 · First seen: 17 Jul 2026