CVE-2026-7754 – IBM Langflow OSS

CVSS 7.7 IMPORTANT Critical - Same Day Deployment

“Security controls lose their value when authentication, validation, and execution boundaries fail together.”

IBM has released updates for Langflow OSS to address multiple Critical and High severity vulnerabilities affecting versions 1.0.0 through 1.10.1. The fixes address hard-coded credentials, authentication bypasses, remote code execution, privilege escalation, arbitrary file write, path traversal, server-side request forgery, insecure deserialization, unsafe code execution, and authorization weaknesses. Several vulnerabilities could allow attackers to gain administrative access, execute arbitrary code, manipulate workflows, overwrite files, or fully compromise affected Langflow deployments.

CVE-2026-13446 has a CVSS score of 9.8, Critical severity. CVE-2026-8476 has a CVSS score of 9.9, Critical severity. CVE-2026-8481 has a CVSS score of 9.9, Critical severity. CVE-2026-8505 has a CVSS score of 9.8, Critical severity. CVE-2026-8635 has a CVSS score of 9.9, Critical severity. CVE-2026-8859 has a CVSS score of 9.9, Critical severity. CVE-2026-9103 has a CVSS score of 9.8, Critical severity. CVE-2026-9135 has a CVSS score of 9.9, Critical severity. CVE-2026-9198 has a CVSS score of 9.8, Critical severity. CVE-2026-9202 has a CVSS score of 9.8, Critical severity. CVE-2026-13445 has a CVSS score of 8.1, High severity. CVE-2026-13448 has a CVSS score of 8.1, High severity. CVE-2026-14499 has a CVSS score of 8.8, High severity. CVE-2026-7667 has a CVSS score of 8.8, High severity. CVE-2026-7755 has a CVSS score of 8.8, High severity. CVE-2026-8056 has a CVSS score of 8.8, High severity. CVE-2026-7754 has a CVSS score of 7.7, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

Key Details

Affected Product
Langflow Langflow
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-918
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.