CVE-2026-78569
published 2026-09-10CVE-2026-78569: IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.65%
49.3th percentile
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | langflow_oss | 1.0.0 – 1.11.5 | — |
| langflow | langflow | >= 1.0.0 < 1.11.6 | 1.11.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Langflow OSS up to 1.11.5 Security Scanner access control
vuldb·2026-09-11·CVSS 8.8
CVE-2026-78569 [HIGH] IBM Langflow OSS up to 1.11.5 Security Scanner access control
A vulnerability, which was classified as critical, has been found in IBM Langflow OSS up to 1.11.5. The impacted element is an unknown function of the component Security Scanner. This manipulation causes improper access controls.
This vulnerability is tracked as CVE-2026-78569. The attack is possible to be carried out remotely. No exploit exists.
GHSA
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
ghsa_unreviewed·2026-09-11
CVE-2026-78569 [HIGH] CWE-78 IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-10
Published