CVE-2026-17626

IBM · Langflow OSS

IBM Langflow OSS versions 1.0.0 through 1.10.3 contain an incorrect privilege assignment vulnerability that allows authenticated users to gain elevated access.

Executive summary

An incorrect privilege assignment vulnerability in IBM Langflow OSS allows authenticated attackers to escalate privileges, potentially leading to a full system compromise.

Vulnerability

This vulnerability involves an improper privilege assignment flaw (CWE-266) within the application. It requires the attacker to be authenticated with low privileges to exploit the issue, which then allows for unauthorized privilege escalation.

Business impact

The ability for a low-privileged user to escalate their access poses a severe threat to data confidentiality, integrity, and availability. With a CVSS score of 8.8, this vulnerability is classified as high severity, as it enables unauthorized administrative actions that could result in full control over the Langflow environment and sensitive data workflows.

Remediation

Immediate Action: Upgrade to IBM Langflow OSS version 1.11.0 or newer immediately to resolve the privilege assignment logic.

Proactive Monitoring: Review user access logs for unusual administrative activity or unexpected changes to user roles and permissions.

Compensating Controls: Implement strict Role Based Access Control (RBAC) policies and limit the exposure of the Langflow management interface to trusted internal networks.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for complete system takeover, organizations using Langflow OSS must prioritize patching to version 1.11.0. Failure to address this vulnerability increases the risk of insider threats or compromised user accounts escalating privileges to perform malicious operations.