CVE-2026-19286
moderateUnauthenticated RCE in IBM Langflow OSS via A2A Public Endpoint (CVE-2026-19286)
CVE-2026-19286 is a critical (CVSS 9.8) code-injection flaw (CWE-94) in IBM Langflow OSS versions 1.0.0 through 1.11.1, caused by improper enforcement of security restrictions on the A2A (agent-to-agent) public endpoint. A remote, unauthenticated attacker can send crafted requests to that network-reachable endpoint (AV:N, AC:L, PR:N, UI:N), bypassing the intended security checks to execute arbitrary code. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity, and availability, effectively compromising the Langflow server in the context of the service account. Any deployment running Langflow OSS 1.0.0–1.11.1 with the A2A public endpoint exposed over the network is affected. Exploitation has not yet been confirmed: the issue is not in CISA KEV, has no known public proof-of-concept, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days.
What to do: Upgrade Langflow OSS to a patched release newer than 1.11.1 as soon as IBM publishes a fixed version, and verify your installed version against the affected range. Until patched, do not expose the A2A public endpoint to untrusted networks: restrict it to trusted sources via firewall/ACL or reverse-proxy authentication, or bind the service to localhost if only local agents use it. Audit internet-facing Langflow instances for exposure and review logs for unexpected requests to the A2A endpoint.
| IBM Langflow OSS | 1.0.0 through 1.11.1 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
- Vendors
- langflow
- Products
- langflow
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.