CVE-2026-18904

8.2

IBM · Langflow OSS

IBM Langflow OSS versions 1.0.0 through 1.11.1 are vulnerable to unauthorized information disclosure and message injection due to a namespace collision involving user identifiers.

Executive summary

IBM Langflow OSS versions 1.0.0 through 1.11.1 are affected by an authorization bypass vulnerability that enables unauthenticated remote attackers to access sensitive data and inject unauthorized messages.

Vulnerability

This vulnerability is caused by a namespace collision between user identifiers, categorized as CWE-639 (Authorization Bypass Through User-Controlled Key). The vulnerability is exploitable by an unauthenticated remote attacker via the network.

Business impact

The vulnerability carries a CVSS score of 8.2, classifying it as a high-severity risk. Successful exploitation allows unauthorized parties to compromise sensitive information and manipulate system communications, which may lead to significant data breaches, loss of operational integrity, and potential reputational damage.

Remediation

Immediate Action: Upgrade IBM Langflow OSS to version 1.11.2 or later as recommended by the vendor.

Proactive Monitoring: Review system and access logs for unusual patterns involving user identifiers or unauthorized message submission attempts.

Compensating Controls: Deploy Web Application Firewall (WAF) rules to inspect incoming traffic for anomalous patterns in user-controlled parameters that might indicate exploitation attempts.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high-severity nature of this vulnerability and the potential for unauthorized data access, organizations should prioritize the update of IBM Langflow OSS to version 1.11.2. Failure to remediate this flaw exposes the environment to unauthenticated remote exploitation, making immediate patch deployment the most effective mitigation strategy.

More IBM CVEs

Sources