Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-9202: IBM Langflow Unauthenticated User Registration Allows Remote Code Execution
CVE-2026-9202
CVE-2026-9202
Summary
IBM Langflow users are at risk of remote code execution due to a security flaw that allows attackers to create new user accounts without authentication. This could allow an attacker to gain full control of a Langflow instance. To mitigate this risk, update to the latest version of IBM Langflow.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | langflow oss | <= 1.10.0 |
Original title
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly...
Original description
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN.
mitre CVSS3.1
9.8
Vulnerability type
CWE-306
Missing Authentication for Critical Function
- https://www.ibm.com/support/pages/node/7278929 vendor-advisory patch
Published: 17 Jul 2026 · Updated: 20 Jul 2026 · First seen: 17 Jul 2026