CVE-2026-9103

Published Jul 17, 2026

Last updated 3 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-9103 is an authentication bypass vulnerability affecting IBM Langflow OSS versions 1.0.0 through 1.10.0. The flaw is located in the `/api/v1/login/auto_login` endpoint, which is designed to streamline local development. When the `AUTO_LOGIN` configuration is enabled—which is the default setting in many affected deployments—the endpoint issues long-lived superuser bearer tokens to any network caller without requiring authentication credentials. This allows unauthenticated network attackers to obtain full administrative access to the Langflow instance. Additionally, permissive cross-origin resource sharing (CORS) settings compound the issue by potentially exposing these tokens to unintended origins. In real-world scenarios, this vulnerability is frequently chained with other flaws to achieve broader system compromise. Specifically, attackers can exploit CVE-2026-9103 to obtain a superuser token and then leverage CVE-2026-8481—a code execution vulnerability in the `/api/v1/validate/code` endpoint—to execute arbitrary Python code on the underlying server. This combined attack path, tracked as CVE-2026-9198, allows unauthenticated remote code execution under the privileges of the Langflow service account. To mitigate the issue, users are advised to upgrade to Langflow version 1.10.1 or later, or disable the auto-login feature by setting the `LANGFLOW_AUTO_LOGIN` environment variable to false.

Description
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unintended origins, increasing the risk of unauthorized access.
Source
psirt@us.ibm.com
NVD status
Analyzed
Products
langflow

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@us.ibm.com
CWE-306

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

5

Configurations

References

Sources include official advisories and independent security research.