VulnWatch VulnWatch
← Back to dashboard
Critical nvd · CVE-2026-9202

CVE-2026-9202: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow

Published Jul 17, 2026 CVSS 9.8

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN.

Affected AI Products

langflow
Get the weekly digest. Every Monday: top AI security stories of the week. Free.