ZeroHour

CVE-2026-18891

large

Improper authentication in IBM Langflow OSS allows unauthenticated flow execution

CVSS 3.1
8.2 high
EPSS
<1%p22
Published
()
Modified
AI analysis

CVE-2026-18891 is an improper authentication flaw (CWE-287) in IBM Langflow OSS versions 1.0.0 through 1.11.1 in which the application fails to properly verify callers before granting access. Because the attack vector is network-based with no privileges or user interaction required (CVSS 3.1: 8.2), a remote unauthenticated attacker can trigger the flaw directly against any reachable Langflow instance. A successful attacker can execute arbitrary flows and access sensitive information processed by the platform, potentially exposing data handled through its AI workflow capabilities. Anyone running an affected Langflow OSS release — self-hosted, containerized, or exposed via its web/API interface — is affected. Exploitation has not been reported: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS currently estimates only a 0.3% chance of exploitation within 30 days.

What to do: Upgrade Langflow OSS to a fixed release beyond 1.11.1 when available and monitor IBM's advisory for the patched version. Until patched, restrict access to the Langflow web/API interface to trusted networks, verify authentication is enforced on any externally reachable instance, and review logs for unexpected flow executions.

Affected
IBM Langflow OSS1.0.0 through 1.11.1 (inclusive)
Estimated exposure
large≈10,000+ internet-exposed Langflow instances, plus an unknown larger number of local/development deployments — Public internet-wide scans during earlier Langflow exploitation campaigns found tens of thousands of exposed instances on its default service port, and Langflow's large open-source community indicates many additional deployments that are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.

Vendors
langflow
Products
langflow
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.