CVE-2026-7664
IBM · Langflow OSS
IBM Langflow OSS suffers from improper authorization enforcement in the Streamable MCP transport endpoint, enabling unauthenticated access to protected project resources and operations.
Executive summary
IBM Langflow OSS contains a critical authorization flaw that allows unauthenticated attackers to manipulate protected project resources and execute unauthorized operations.
Vulnerability
The vulnerability exists within the Streamable MCP transport endpoint, which fails to properly enforce authorization checks. This allows an unauthenticated attacker to interact with protected MCP projects and perform unauthorized actions.
Business impact
With a CVSS score of 9.8, this vulnerability carries a high risk of unauthorized data access and manipulation. Exploitation could lead to the exposure of sensitive proprietary project data or the malicious modification of operational workflows, resulting in significant business disruption and potential loss of intellectual property.
Remediation
Immediate Action: Update IBM Langflow OSS to the latest version as recommended by the vendor to enforce proper authorization controls.
Proactive Monitoring: Review access logs for unusual patterns of interaction with the MCP transport endpoint or unauthorized attempts to access project-specific resources.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests directed at the MCP transport endpoint.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a severe risk to project integrity and data security. Administrators must apply the vendor-provided patch immediately to ensure that authorization mechanisms are correctly enforced and that unauthorized access is blocked.