CVE-2026-8056
published 2026-07-17CVE-2026-8056: IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in…
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.53%
42.8th percentile
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter filtering mechanism within the `apply_tweaks()` function.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | langflow_oss | 1.0.0 – 1.10.0 | — |
| langflow | langflow | >= 1.0.0 < 1.10.1 | 1.10.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API.
ghsa_unreviewed·2026-07-17
CVE-2026-8056 [HIGH] CWE-94 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API.
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter filtering mechanism within the `apply_tweaks()` function.
VulDB
IBM Langflow OSS up to 1.10.0 API apply_tweaks privilege escalation
vuldb·2026-07-17·CVSS 8.8
CVE-2026-8056 [HIGH] IBM Langflow OSS up to 1.10.0 API apply_tweaks privilege escalation
A vulnerability was found in IBM Langflow OSS up to 1.10.0. It has been rated as critical. Affected by this vulnerability is the function apply_tweaks of the component API. Performing a manipulation results in privilege escalation.
This vulnerability is known as CVE-2026-8056. Remote exploitation of the attack is possible. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-17
Published