{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-12945/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-12945"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Langflow OSS (1.10.1)"],"_cs_severities":["high"],"_cs_tags":["cve-2026-12945","authorization-bypass","cwe-639"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Langflow OSS versions 1.0.0 through 1.10.1 are susceptible to an authorization bypass vulnerability identified as CVE-2026-12945. The vulnerability, categorized as CWE-639 (Authorization Bypass Through User-Controlled Key), stems from improper access controls within the application's log retrieval functionality and its build job management endpoints. An attacker with standard authenticated access can manipulate object identifiers to interact with build jobs that they are not authorized to view or modify. This flaw enables unauthorized access to sensitive build logs and potential disruption of build processes, impacting the integrity and confidentiality of the development workflow within environments utilizing the affected versions of Langflow OSS.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker authenticates to the target IBM Langflow OSS instance with a low-privileged user account.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies the application's API endpoints responsible for log retrieval and build job management.\u003c/li\u003e\n\u003cli\u003eThe attacker observes that requests to these endpoints include identifiers (e.g., job IDs or user IDs) that can be manipulated.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP request to the build job endpoint, replacing legitimate identifiers with target identifiers corresponding to other users' jobs.\u003c/li\u003e\n\u003cli\u003eThe server fails to validate whether the current authenticated user has sufficient permissions to access the specified resource.\u003c/li\u003e\n\u003cli\u003eThe application processes the request and returns the sensitive logs or executes unauthorized actions (manipulation) on the target build job.\u003c/li\u003e\n\u003cli\u003eThe attacker repeats this process for multiple job IDs to exfiltrate logs or disrupt build pipelines.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability permits unauthorized access to build logs and the ability to manipulate build jobs belonging to other users. In a CI/CD environment, this can lead to the exposure of proprietary code, environment variables, credentials present in build logs, or the intentional corruption of software build pipelines, resulting in potential service disruption or supply chain compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade IBM Langflow OSS to a patched version beyond 1.10.1 immediately to remediate CVE-2026-12945.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) or API gateway rules to inspect requests to build endpoints for unauthorized identifier modification (insecure direct object reference patterns).\u003c/li\u003e\n\u003cli\u003eReview access logs for high-frequency or anomalous requests to build management and log retrieval API endpoints originating from standard user accounts.\u003c/li\u003e\n\u003cli\u003eImplement strict role-based access control (RBAC) policies and ensure that all server-side endpoints enforce ownership validation for requested resources.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-30T17:30:10Z","date_published":"2026-07-30T17:30:10Z","id":"https://feed.craftedsignal.io/briefs/2026-07-langflow-auth-bypass/","summary":"IBM Langflow OSS versions 1.0.0 through 1.10.1 contain an authorization bypass vulnerability (CVE-2026-12945) allowing authenticated users to access and manipulate build jobs of other users.","title":"Authorization Bypass Vulnerability in IBM Langflow OSS","url":"https://feed.craftedsignal.io/briefs/2026-07-langflow-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-12945","version":"https://jsonfeed.org/version/1.1"}