CVE-2026-9198
Published Jul 17, 2026
Last updated 21 hours ago
AI description
CVE-2026-9198 is an unauthenticated remote code execution vulnerability affecting IBM Langflow OSS versions 1.0.0 through 1.10.0. This flaw allows attackers to gain full control over default Langflow deployments by exploiting a chain of two API endpoints. Specifically, the vulnerability leverages the `/api/v1/auto_login` endpoint, which issues SUPERUSER tokens to any network caller without requiring authentication. Subsequently, attackers can utilize the `/api/v1/validate/code` endpoint to execute arbitrary Python code via `exec()`, leading to full remote code execution. This issue is classified under CWE-94, indicating improper control of code generation. The vulnerability has been addressed in Langflow version 1.10.1.
- Description
- IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
- Products
- langflow
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- IBM Langflow Code Injection Vulnerability
- Exploit added on
- Aug 4, 2026
- Exploit action due
- Aug 7, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- psirt@us.ibm.com
- CWE-94
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
15
New zero-days & CVEs threaten data in transit. Langflow RCE (CVE-2026-9198), SonicWall bypass (CVE-2026-15409), & Cisco FMC static creds (CVE-2026-20316) enable RCE/access, compromising privacy & integrity. Urgent patching vital. #Cybersecurity #ZeroDay #News
@YourAnon_irc
5 Aug 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ CYBER BULLETIN | 05/08/2026 Three relevant updates for today: 1. CISA adds three actively exploited flaws to the KEV catalog CISA has listed CVE-2026-9198 (IBM Langflow code injection enabling unauthenticated RCE on default installs), CVE-2026-18556 (N-able N-central ht
@FrontieraTechIT
5 Aug 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 CVE-of-the-Day: CVE-2026-9198 — IBM Langflow (AI agent builder), unauth RCE CVSS: 9.8 | EPSS: 0.44% Chaining two API endpoints lets an unauthenticated attacker get a superuser token, then run arbitrary Python on the host. No login needed. #CVE #infosec #langflow #AISecurit
@YourDailyCVE
5 Aug 2026
5 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🔒 #CyberSecurity CVE-2026-9198: Langflow RCE Actively Exploited — Detection and Hardening Guide "On August 5, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added…" 🔗 https://t.co/dl2NQgzPtG #CyberSecurity #ThreatIntel #cve #zeroday #patchtue
@SecurityAr58409
5 Aug 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added CVE-2026-9198, CVE-2026-34486 and CVE-2026-18556 to the KEV catalog. CVE-2026-9198 lets unauthenticated attackers chain Langflow APIs for code execution. CVE-2026-34486 bypasses Apache Tomcat EncryptInterceptor encryption. N-central CVE-2026-18556 enables auth bypass;
@WorldCyberNewsX
5 Aug 2026
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISAが既知の悪用された脆弱性3件をカタログに追加 CISA Adds Three Known Exploited Vulnerabilities to Catalog #CISA (Aug 4) CVE-2026-9198 IBM Langflow コードインジェクションの脆弱性 CVE-2026-18556 N-able N-central認証バイパス(代替パ
@foxbook
5 Aug 2026
295 Impressions
1 Retweet
2 Likes
3 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-9198: IBM Langflow Code Injection Exploitation — Detection and Remedia… "On August 4, 2026, CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities…" 🔗 https://t.co/aWUaWDqkJI #CyberSecurity #ThreatIntel #cve20269198 #critical #ci
@SecurityAr58409
5 Aug 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が、既知の悪用された脆弱性カタログに、LangflowのCVE-2026-9198、N-able N-centralのCVE-2026-18556、Apache TomcatのCVE-2026-34486を追加。対処期限は3日後の8/7。ランサムウ
@__kokumoto
4 Aug 2026
774 Impressions
0 Retweets
3 Likes
3 Bookmarks
1 Reply
0 Quotes
🛡️We added IBM Langflow vulnerability CVE-2026-9198, N-able N-central vulnerability CVE-2026-18556 & Apache Tomcat vulnerability CVE-2026-34486 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity
@CISACyber
4 Aug 2026
9071 Impressions
14 Retweets
38 Likes
8 Bookmarks
5 Replies
1 Quote
⚠️ Vulnerabilidades en productos IBM ❗ CVE-2026-9198 ❗ CVE-2026-9103 ❗ CVE-2026-8481 ➡️ Más info: https://t.co/HvNQ4gvgL8 https://t.co/R2JRwuxwAc
@CERTpy
29 Jul 2026
159 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A32785B1-3CF7-4BD0-B6F8-1AA77D4E565B",
"versionEndExcluding": "1.10.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]