Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-9202: IBM Langflow Unauthenticated User Registration Allows Remote Code Execution

CVE-2026-9202 · published 2 months ago
Summary

IBM Langflow users are at risk of remote code execution due to a security flaw that allows attackers to create new user accounts without authentication. This could allow an attacker to gain full control of a Langflow instance. To mitigate this risk, update to the latest version of IBM Langflow.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm langflow oss <= 1.10.0
Original advisory text
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly...
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN.
References
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published17 Jul 2026
Updated25 Sep 2026
First seen17 Jul 2026
Sources
CVE-2026-9202 · NVD
CVE-2026-9202 · MITRE
CVE-2026-9202 · OSV
Track software like this
Free during beta