CVE-2026-9198

Published Jul 17, 2026

Last updated 21 hours ago

Exploit knownCVSS critical 9.8
Langflow
web application
Zero-day
IBM Langflow OSS

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-9198 is an unauthenticated remote code execution vulnerability affecting IBM Langflow OSS versions 1.0.0 through 1.10.0. This flaw allows attackers to gain full control over default Langflow deployments by exploiting a chain of two API endpoints. Specifically, the vulnerability leverages the `/api/v1/auto_login` endpoint, which issues SUPERUSER tokens to any network caller without requiring authentication. Subsequently, attackers can utilize the `/api/v1/validate/code` endpoint to execute arbitrary Python code via `exec()`, leading to full remote code execution. This issue is classified under CWE-94, indicating improper control of code generation. The vulnerability has been addressed in Langflow version 1.10.1.

Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
Source
psirt@us.ibm.com
NVD status
Analyzed
Products
langflow

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
IBM Langflow Code Injection Vulnerability
Exploit added on
Aug 4, 2026
Exploit action due
Aug 7, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

psirt@us.ibm.com
CWE-94

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

15

  1. New zero-days & CVEs threaten data in transit. Langflow RCE (CVE-2026-9198), SonicWall bypass (CVE-2026-15409), & Cisco FMC static creds (CVE-2026-20316) enable RCE/access, compromising privacy & integrity. Urgent patching vital. #Cybersecurity #ZeroDay #News

    @YourAnon_irc

    5 Aug 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🛡️ CYBER BULLETIN | 05/08/2026 Three relevant updates for today: 1. CISA adds three actively exploited flaws to the KEV catalog CISA has listed CVE-2026-9198 (IBM Langflow code injection enabling unauthenticated RCE on default installs), CVE-2026-18556 (N-able N-central ht

    @FrontieraTechIT

    5 Aug 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 🚨 CVE-of-the-Day: CVE-2026-9198 — IBM Langflow (AI agent builder), unauth RCE CVSS: 9.8 | EPSS: 0.44% Chaining two API endpoints lets an unauthenticated attacker get a superuser token, then run arbitrary Python on the host. No login needed. #CVE #infosec #langflow #AISecurit

    @YourDailyCVE

    5 Aug 2026

    5 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 🔒 #CyberSecurity CVE-2026-9198: Langflow RCE Actively Exploited — Detection and Hardening Guide "On August 5, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added…" 🔗 https://t.co/dl2NQgzPtG #CyberSecurity #ThreatIntel #cve #zeroday #patchtue

    @SecurityAr58409

    5 Aug 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CISA added CVE-2026-9198, CVE-2026-34486 and CVE-2026-18556 to the KEV catalog. CVE-2026-9198 lets unauthenticated attackers chain Langflow APIs for code execution. CVE-2026-34486 bypasses Apache Tomcat EncryptInterceptor encryption. N-central CVE-2026-18556 enables auth bypass;

    @WorldCyberNewsX

    5 Aug 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CISAが既知の悪用された脆弱性3件をカタログに追加 CISA Adds Three Known Exploited Vulnerabilities to Catalog #CISA (Aug 4) CVE-2026-9198 IBM Langflow コードインジェクションの脆弱性 CVE-2026-18556 N-able N-central認証バイパス(代替パ

    @foxbook

    5 Aug 2026

    295 Impressions

    1 Retweet

    2 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  7. 🔒 #CyberSecurity CVE-2026-9198: IBM Langflow Code Injection Exploitation — Detection and Remedia… "On August 4, 2026, CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities…" 🔗 https://t.co/aWUaWDqkJI #CyberSecurity #ThreatIntel #cve20269198 #critical #ci

    @SecurityAr58409

    5 Aug 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が、既知の悪用された脆弱性カタログに、LangflowのCVE-2026-9198、N-able N-centralのCVE-2026-18556、Apache TomcatのCVE-2026-34486を追加。対処期限は3日後の8/7。ランサムウ

    @__kokumoto

    4 Aug 2026

    774 Impressions

    0 Retweets

    3 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  9. 🛡️We added IBM Langflow vulnerability CVE-2026-9198, N-able N-central vulnerability CVE-2026-18556 & Apache Tomcat vulnerability CVE-2026-34486 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity

    @CISACyber

    4 Aug 2026

    9071 Impressions

    14 Retweets

    38 Likes

    8 Bookmarks

    5 Replies

    1 Quote

  10. ⚠️ Vulnerabilidades en productos IBM ❗ CVE-2026-9198 ❗ CVE-2026-9103 ❗ CVE-2026-8481 ➡️ Más info: https://t.co/HvNQ4gvgL8 https://t.co/R2JRwuxwAc

    @CERTpy

    29 Jul 2026

    159 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations