Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-9103: IBM Langflow: Unauthenticated Access to Administrative Features

CVE-2026-9103 CVE-2026-9103
Summary

IBM Langflow OSS versions 1.0.0 to 1.10.0 have a security issue that allows unauthorized access to administrative features. This can happen if a network attacker uses a feature called auto-login. To protect yourself, update IBM Langflow to the latest version and review your configuration settings, especially those related to auto-login and cross-origin resource sharing.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
ibm langflow oss <= 1.10.0
Original title
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-liv...
Original description
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unintended origins, increasing the risk of unauthorized access.
mitre CVSS3.1 9.8
Vulnerability type
CWE-306 Missing Authentication for Critical Function
Published: 17 Jul 2026 · Updated: 20 Jul 2026 · First seen: 17 Jul 2026