CVE-2026-81268
largeInsufficient API key expiration in IBM Langflow OSS lets deactivated users keep access
IBM Langflow OSS versions 1.0.0 through 1.11.5 fail to properly expire API keys after a user is deactivated, an insufficient session expiration flaw tracked as CWE-613. A remote attacker who still holds the API key of a deactivated user can authenticate with low privileges, with no user interaction required. Successful exploitation allows the attacker to execute flows and obtain sensitive information, with high confidentiality and integrity impact reflected in the CVSS 3.1 score of 8.1. Any deployment of an affected version in which users have been deactivated without their API keys being revoked is affected, making this primarily an offboarding and credential-lifecycle risk for multi-user instances. No public proof-of-concept is known, the flaw is not in CISA KEV, and there are no confirmed reports of in-the-wild exploitation.
What to do: Upgrade Langflow OSS to a fixed release beyond 1.11.5 as soon as IBM publishes one, and monitor the IBM PSIRT advisory for the fixed version. As interim mitigation, revoke or rotate the API keys of all deactivated users and add offboarding checks that deactivate keys whenever a user is removed. Review Langflow access and audit logs for flow executions attributable to deactivated accounts, and restrict network access to Langflow instances where possible.
| IBM Langflow OSS | 1.0.0 through 1.11.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.
- Vendors
- langflow
- Products
- langflow
- Weakness
- CWE-613
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.