Skip to content
HighVulnerability

CVE-2026-104335: IBM Langflow OSS remote code execution due to improper access control

Identifier
CVE-2026-104335
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.6%

Summary

IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a flaw tracked as CVE-2026-104335. Due to improper access control, a remote authenticated attacker could execute arbitrary code.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.