CVE-2026-13444

IBM · Langflow OSS

IBM Langflow OSS contains a .NET impersonation misconfiguration that may allow authenticated users to perform unauthorized actions.

Executive summary

An authentication-related misconfiguration in IBM Langflow OSS version 1.0.0 through 1.10.1 poses a high risk of unauthorized data access and integrity compromise.

Vulnerability

This vulnerability involves a CWE-520 improper .NET impersonation configuration. The issue requires a low-privileged authenticated user to trigger, potentially allowing the attacker to escalate privileges or perform actions with the identity of another user.

Business impact

Successful exploitation allows an authenticated attacker to gain unauthorized access to sensitive data or modify system configurations. With a CVSS score of 8.1, the risk is classified as high because it directly impacts the confidentiality and integrity of the application. This could lead to significant operational disruption and a breach of internal security policies.

Remediation

Immediate Action: Upgrade to IBM Langflow OSS version 1.10.2 as specified by the vendor.

Proactive Monitoring: Review application access logs for unusual account activity or unauthorized requests originating from low-privileged user accounts.

Compensating Controls: Implement strict access control lists and evaluate the necessity of impersonation features within the environment to limit the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score, organizations should prioritize the update to version 1.10.2 to remediate this misconfiguration. Failure to apply this patch exposes the environment to potential privilege escalation and unauthorized data manipulation by authenticated actors.