CVE-2026-8476 – IBM Langflow OSS
“Security controls lose their value when authentication, validation, and execution boundaries fail together.”
IBM has released updates for Langflow OSS to address multiple Critical and High severity vulnerabilities affecting versions 1.0.0 through 1.10.1. The fixes address hard-coded credentials, authentication bypasses, remote code execution, privilege escalation, arbitrary file write, path traversal, server-side request forgery, insecure deserialization, unsafe code execution, and authorization weaknesses. Several vulnerabilities could allow attackers to gain administrative access, execute arbitrary code, manipulate workflows, overwrite files, or fully compromise affected Langflow deployments.
CVE-2026-13446 has a CVSS score of 9.8, Critical severity. CVE-2026-8476 has a CVSS score of 9.9, Critical severity. CVE-2026-8481 has a CVSS score of 9.9, Critical severity. CVE-2026-8505 has a CVSS score of 9.8, Critical severity. CVE-2026-8635 has a CVSS score of 9.9, Critical severity. CVE-2026-8859 has a CVSS score of 9.9, Critical severity. CVE-2026-9103 has a CVSS score of 9.8, Critical severity. CVE-2026-9135 has a CVSS score of 9.9, Critical severity. CVE-2026-9198 has a CVSS score of 9.8, Critical severity. CVE-2026-9202 has a CVSS score of 9.8, Critical severity. CVE-2026-13445 has a CVSS score of 8.1, High severity. CVE-2026-13448 has a CVSS score of 8.1, High severity. CVE-2026-14499 has a CVSS score of 8.8, High severity. CVE-2026-7667 has a CVSS score of 8.8, High severity. CVE-2026-7755 has a CVSS score of 8.8, High severity. CVE-2026-8056 has a CVSS score of 8.8, High severity. CVE-2026-7754 has a CVSS score of 7.7, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.
Key Details
- Affected Product
- Langflow Langflow
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-502