CVE-2026-7664

IBM · Langflow OSS

IBM Langflow OSS suffers from improper authorization enforcement in the Streamable MCP transport endpoint, enabling unauthenticated access to protected project resources and operations.

Executive summary

IBM Langflow OSS contains a critical authorization flaw that allows unauthenticated attackers to manipulate protected project resources and execute unauthorized operations.

Vulnerability

The vulnerability exists within the Streamable MCP transport endpoint, which fails to properly enforce authorization checks. This allows an unauthenticated attacker to interact with protected MCP projects and perform unauthorized actions.

Business impact

With a CVSS score of 9.8, this vulnerability carries a high risk of unauthorized data access and manipulation. Exploitation could lead to the exposure of sensitive proprietary project data or the malicious modification of operational workflows, resulting in significant business disruption and potential loss of intellectual property.

Remediation

Immediate Action: Update IBM Langflow OSS to the latest version as recommended by the vendor to enforce proper authorization controls.

Proactive Monitoring: Review access logs for unusual patterns of interaction with the MCP transport endpoint or unauthorized attempts to access project-specific resources.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests directed at the MCP transport endpoint.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a severe risk to project integrity and data security. Administrators must apply the vendor-provided patch immediately to ensure that authorization mechanisms are correctly enforced and that unauthorized access is blocked.