AI description
CVE-2026-9103 is an authentication bypass vulnerability affecting IBM Langflow OSS versions 1.0.0 through 1.10.0. The flaw is located in the `/api/v1/login/auto_login` endpoint, which is designed to streamline local development. When the `AUTO_LOGIN` configuration is enabled—which is the default setting in many affected deployments—the endpoint issues long-lived superuser bearer tokens to any network caller without requiring authentication credentials. This allows unauthenticated network attackers to obtain full administrative access to the Langflow instance. Additionally, permissive cross-origin resource sharing (CORS) settings compound the issue by potentially exposing these tokens to unintended origins. In real-world scenarios, this vulnerability is frequently chained with other flaws to achieve broader system compromise. Specifically, attackers can exploit CVE-2026-9103 to obtain a superuser token and then leverage CVE-2026-8481—a code execution vulnerability in the `/api/v1/validate/code` endpoint—to execute arbitrary Python code on the underlying server. This combined attack path, tracked as CVE-2026-9198, allows unauthenticated remote code execution under the privileges of the Langflow service account. To mitigate the issue, users are advised to upgrade to Langflow version 1.10.1 or later, or disable the auto-login feature by setting the `LANGFLOW_AUTO_LOGIN` environment variable to false.
- Description
- IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unintended origins, increasing the risk of unauthorized access.
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
- Products
- langflow
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- psirt@us.ibm.com
- CWE-306
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
5
Default Langflow - auto_login mints you a SUPERUSER JWT. Then validate/code just exec()s your Python. CVE-2026-9198 = CVE-2026-9103 + CVE-2026-8481. IBM Langflow OSS 1.0.0-1.10.0 when AUTO_LOGIN is on (default pre-1.5). Chain: unauth GET /api/v1/auto_login —> SUPERUSER bea
@0xManan
10 Oct 2026
2505 Impressions
3 Retweets
31 Likes
10 Bookmarks
2 Replies
1 Quote
🚨 CVE-2026-9103 - critical 🚨 Langflow OSS - Superuser Token Issuance > Langflow OSS with default AUTO_LOGIN exposes `/api/v1/auto_login`, which returns a su... 👾 https://t.co/jGmvAhal7h @pdnuclei #NucleiTemplates #cve
@pdnuclei_bot
18 Sept 2026
103 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
⚠️ Vulnerabilidades en productos IBM ❗ CVE-2026-9198 ❗ CVE-2026-9103 ❗ CVE-2026-8481 ➡️ Más info: https://t.co/HvNQ4gvgL8 https://t.co/R2JRwuxwAc
@CERTpy
29 Jul 2026
159 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A32785B1-3CF7-4BD0-B6F8-1AA77D4E565B",
"versionEndExcluding": "1.10.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
"matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
"matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1",
"vulnerable": false
},
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]