CVE-2026-17626
IBM · Langflow OSS
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain an incorrect privilege assignment vulnerability that allows authenticated users to gain elevated access.
Executive summary
An incorrect privilege assignment vulnerability in IBM Langflow OSS allows authenticated attackers to escalate privileges, potentially leading to a full system compromise.
Vulnerability
This vulnerability involves an improper privilege assignment flaw (CWE-266) within the application. It requires the attacker to be authenticated with low privileges to exploit the issue, which then allows for unauthorized privilege escalation.
Business impact
The ability for a low-privileged user to escalate their access poses a severe threat to data confidentiality, integrity, and availability. With a CVSS score of 8.8, this vulnerability is classified as high severity, as it enables unauthorized administrative actions that could result in full control over the Langflow environment and sensitive data workflows.
Remediation
Immediate Action: Upgrade to IBM Langflow OSS version 1.11.0 or newer immediately to resolve the privilege assignment logic.
Proactive Monitoring: Review user access logs for unusual administrative activity or unexpected changes to user roles and permissions.
Compensating Controls: Implement strict Role Based Access Control (RBAC) policies and limit the exposure of the Langflow management interface to trusted internal networks.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for complete system takeover, organizations using Langflow OSS must prioritize patching to version 1.11.0. Failure to address this vulnerability increases the risk of insider threats or compromised user accounts escalating privileges to perform malicious operations.