CRITICAL
Unauthenticated User Registration Could Lead to Remote Code Execution
Published Jul 17, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.50%
Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN.
Affected products
-
- Version 1.0.0StatusaffectedConstraints<=1.10.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| IBM | Langflow OSS | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.1 https://pypi.org/project/langflow/
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45235 Advisory
- https://www.ibm.com/support/pages/node/7278929 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45235 | Advisory | |
| https://www.ibm.com/support/pages/node/7278929 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Jul 17, 2026
Updated Jul 18, 2026
Reserved May 21, 2026
Link CVE-2026-9202
CISA Vulnrichment
Updated Jul 17, 2026
ENISA EUVD
EUVD-2026-45235 Assigner ibm
Published Jul 17, 2026
Updated Jul 18, 2026
Exploited since n/a
Link EUVD-2026-45235