{"data":{"id":"a8453895-0fab-4882-9015-7058e40cf374","title":"CVE-2026-17628: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account d","summary":"IBM Langflow OSS (an open-source tool for building AI applications) versions 1.0.0 through 1.10.2 has a security flaw where an attacker who is already logged into an account can change another user's password because the system doesn't properly verify who should be allowed to make that change. This allows unauthorized account takeovers for authenticated users.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-17628","publishedAt":"2026-09-14T20:16:42.140Z","cveId":"CVE-2026-17628","cweIds":["CWE-287"],"cvssScore":"5.4","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow OSS"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-14T20:16:42.140Z","capecIds":["CAPEC-114"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}