{"data":{"id":"cd06c705-8640-4ca0-9d8b-c75b639f015f","title":"CVE-2026-9202: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow","summary":"IBM Langflow OSS (open-source software) versions 1.0.0 through 1.10.0 has a critical flaw that allows attackers without login credentials to create unlimited user accounts. When a specific deployment setting called NEW_USER_IS_ACTIVE is enabled, these newly created accounts become immediately usable and can access RCE endpoints (remote code execution, where an attacker can run commands on a system they don't own), completely bypassing security controls.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9202","publishedAt":"2026-07-17T18:17:17.490Z","cveId":"CVE-2026-9202","cweIds":["CWE-306"],"cvssScore":"9.8","cvssSeverity":"critical","severity":"critical","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow OSS"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-17T18:17:17.490Z","capecIds":["CAPEC-115"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","availability"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]}}