Improper Access Control in IBM Langflow OSS Leads to Remote Code Execution
IBM Langflow OSS versions 1.0.0 through 1.12.2 contain an improper access control vulnerability (CVE-2026-104335) that allows an authenticated remote attacker to execute arbitrary code.
CVE search metadata
CVE search record: CVE-2026-104335. Severity: high. CVSS: 8.8. KEV: no. Product: Langflow OSS (1.0.0 through 1.12.2), Langflow OSS (1.0.0 - 1.12.2). Brief: Improper Access Control in IBM Langflow OSS Leads to Remote Code Execution. Brief link: https://feed.craftedsignal.io/briefs/2026-10-104335/
What's new
- 1. added coverage for Langflow OSS (1.0.0 - 1.12.2) Oct 7, 02:59 via nvd
IBM Langflow OSS, an open-source visual framework for building multi-agent AI applications, is affected by a critical vulnerability, CVE-2026-104335. This flaw exists in versions 1.0.0 through 1.12.2 and stems from improper access control mechanisms within the application. An attacker with authenticated access can leverage this vulnerability to execute arbitrary code on the underlying host system. Given that Langflow environments often handle sensitive API keys, model configurations, and data processing tasks, this vulnerability represents a significant risk for unauthorized access, lateral movement, and data exfiltration. Organizations deploying IBM Langflow OSS should prioritize upgrading to a patched version once available and enforce strict access controls on the management interface.
Impact
Successful exploitation of this vulnerability allows an authenticated attacker to bypass intended access restrictions and achieve arbitrary code execution. This could result in a complete compromise of the Langflow application instance, unauthorized access to connected AI services or databases, and the potential for exfiltration of intellectual property or sensitive model data.
Recommendation
Prioritize the upgrade of all IBM Langflow OSS instances to a version later than 1.12.2. Monitor administrative access logs for unusual login patterns or actions performed by users with elevated privileges. Given the lack of specific exploitation telemetry, focus on identifying unauthorized attempts to access or modify workflow configurations within the Langflow interface.
Immediate actions
Upgrade IBM Langflow OSS to a version beyond 1.12.2
Mitigations
Restrict network access to the Langflow web interface to known management IPs
CVE-2026-104335