CVE-2026-19875: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abu
Summary
IBM Langflow OSS versions 1.0.0 through 1.10.0 have a security flaw where the registration endpoint lacks authentication (a check to verify who is making requests), allowing remote attackers to change the administrator's email address and potentially use the server to send spam or malicious emails. This vulnerability is classified as CWE-306 (missing authentication for critical function).
Vulnerability Details
7.5(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
network
low
none
none
August 19, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19875
First tracked: August 19, 2026 at 08:09 PM
Classified by LLM (prompt v3) · confidence: 92%