Back

CRITICAL

Unauthenticated User Registration Could Lead to Remote Code Execution

Published Jul 17, 2026

Description

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN.

Affected products

Remediation

Vendor solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.1 https://pypi.org/project/langflow/

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Jul 17, 2026
Updated Jul 18, 2026
Reserved May 21, 2026
CISA Vulnrichment
Updated Jul 17, 2026
NVD
Status Analyzed
Modified Jul 24, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ibm
Published Jul 17, 2026
Updated Jul 18, 2026
Exploited since n/a
EUVD-2026-45235