CVE-2026-17632 – IBM Langflow OSS

CVSS 8.8 IMPORTANT High with EoP or RCE – Expedited Deployment

“Multiple high-severity flaws expose Langflow to code execution, security bypasses, and sensitive data compromise.”

IBM Langflow OSS is affected by 16 High-severity vulnerabilities, primarily impacting versions 1.0.0 through 1.10.3. CVE-2026-17626, CVE-2026-17632, CVE-2026-8182, CVE-2026-8478, and CVE-2026-9201 have CVSS scores of 8.8, High severity. CVE-2026-17633 and CVE-2026-9077 have CVSS scores of 8.5, High severity. CVE-2026-9196 has a CVSS score of 8.1, High severity. The remaining eight vulnerabilities have CVSS scores ranging from 7.1 to 7.7, all High severity.

The flaws include arbitrary code and command execution, authentication and authorization bypass, host-file access, directory traversal, SSRF, weak cryptography, and cross-user information disclosure. Several vulnerabilities can expose the Langflow backend or underlying host to direct compromise.

CVE List:
CVE-2026-17626 (8.8)
CVE-2026-17632 (8.8)
CVE-2026-17633 (8.5)
CVE-2026-8182 (8.8)
CVE-2026-8478 (8.8)
CVE-2026-9077 (8.5)
CVE-2026-9196 (8.1)
CVE-2026-9201 (8.8)
CVE-2026-17625 (7.2)
CVE-2026-17630 (7.2)
CVE-2026-8183 (7.7)
CVE-2026-8446 (7.5)
CVE-2026-8470 (7.4)
CVE-2026-9081 (7.1)
CVE-2026-9130 (7.1)
CVE-2026-9205 (7.4)

The affected Langflow releases contain a broad attack surface across MCP, components, and backend validation.

Key Details

Affected Product
Langflow Langflow
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-94
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.