{"data":{"id":"a8ce7d88-4330-46ff-8154-a4f087ba0c5d","title":"CVE-2026-19875: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abu","summary":"IBM Langflow OSS versions 1.0.0 through 1.10.0 have a security flaw where the registration endpoint lacks authentication (a check to verify who is making requests), allowing remote attackers to change the administrator's email address and potentially use the server to send spam or malicious emails. This vulnerability is classified as CWE-306 (missing authentication for critical function).","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19875","publishedAt":"2026-08-19T18:16:36.557Z","cveId":"CVE-2026-19875","cweIds":["CWE-306"],"cvssScore":"7.5","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-19T18:16:36.557Z","capecIds":["CAPEC-115"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}