IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unintended origins, increasing the risk of unauthorized access.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7278926 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
20 Jul 2026, 18:22
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.ibm.com/support/pages/node/7278926 - Vendor Advisory | |
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| First Time |
Apple macos
Langflow langflow Linux Apple Linux linux Kernel Microsoft windows Microsoft Langflow |
17 Jul 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-17 19:17
Updated : 2026-07-23 05:16
NVD link : CVE-2026-9103
Mitre link : CVE-2026-9103
CVE.ORG link : CVE-2026-9103
JSON object : View
Products Affected
langflow
- langflow
microsoft
- windows
apple
- macos
linux
- linux_kernel
CWE
CWE-306
Missing Authentication for Critical Function
