ZeroHour

CVE-2026-19286

moderate

Unauthenticated RCE in IBM Langflow OSS via A2A Public Endpoint (CVE-2026-19286)

CVSS 3.1
9.8 critical
EPSS
<1%p48
Published
()
Modified
AI analysis

CVE-2026-19286 is a critical (CVSS 9.8) code-injection flaw (CWE-94) in IBM Langflow OSS versions 1.0.0 through 1.11.1, caused by improper enforcement of security restrictions on the A2A (agent-to-agent) public endpoint. A remote, unauthenticated attacker can send crafted requests to that network-reachable endpoint (AV:N, AC:L, PR:N, UI:N), bypassing the intended security checks to execute arbitrary code. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity, and availability, effectively compromising the Langflow server in the context of the service account. Any deployment running Langflow OSS 1.0.0–1.11.1 with the A2A public endpoint exposed over the network is affected. Exploitation has not yet been confirmed: the issue is not in CISA KEV, has no known public proof-of-concept, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days.

What to do: Upgrade Langflow OSS to a patched release newer than 1.11.1 as soon as IBM publishes a fixed version, and verify your installed version against the affected range. Until patched, do not expose the A2A public endpoint to untrusted networks: restrict it to trusted sources via firewall/ACL or reverse-proxy authentication, or bind the service to localhost if only local agents use it. Audit internet-facing Langflow instances for exposure and review logs for unexpected requests to the A2A endpoint.

Affected
IBM Langflow OSS1.0.0 through 1.11.1 (inclusive)
Estimated exposure
moderate≈10k–100k users overall, with likely only a few thousand internet-exposed Langflow deployments — Langflow is a widely adopted open-source agent-building framework with a large developer community, but it is most often run locally or in internal development environments, so the internet-facing instance population observed in public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.

Vendors
langflow
Products
langflow
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.