Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-9202: IBM Langflow Unauthenticated User Registration Allows Remote Code Execution
CVE-2026-9202 · published 2 months ago
Summary
IBM Langflow users are at risk of remote code execution due to a security flaw that allows attackers to create new user accounts without authentication. This could allow an attacker to gain full control of a Langflow instance. To mitigate this risk, update to the latest version of IBM Langflow.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | langflow oss | <= 1.10.0 |
Original advisory text
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly...
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN.
References
- https://www.ibm.com/support/pages/node/7278929 vendor-advisory patch
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published17 Jul 2026
Updated25 Sep 2026
First seen17 Jul 2026
Track software like this
Free during beta