CVE-2026-9103
published 2026-07-17CVE-2026-9103: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login…
PriorityP279critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
3.21%
87.7th percentile
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unintended origins, increasing the risk of unauthorized access.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | langflow_oss | 1.0.0 – 1.10.0 | — |
| langflow | langflow | >= 1.0.0 < 1.10.1 | 1.10.1 |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint.
ghsa_unreviewed·2026-07-17
CVE-2026-9103 [CRITICAL] CWE-306 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint.
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unintended origins, increasing the risk of unauthorized access.
VulDB
IBM Langflow OSS up to 1.10.0 Auto Login Endpoint /api/v1/login/auto_login improper authentication
vuldb·2026-07-17·CVSS 9.8
CVE-2026-9103 [CRITICAL] IBM Langflow OSS up to 1.10.0 Auto Login Endpoint /api/v1/login/auto_login improper authentication
A vulnerability categorized as critical has been discovered in IBM Langflow OSS up to 1.10.0. Impacted is the function auto_login of the file /api/v1/login/auto_login of the component Auto Login Endpoint. Executing a manipulation can lead to improper authentication.
This vulnerability is tracked as CVE-2026-9103. The attack can be launched remotely. No exploit exists.
No detection rules found.
Nuclei
Langflow OSS - Superuser Token Issuance
nuclei·CVSS 9.8
CVE-2026-9103 [CRITICAL] Langflow OSS - Superuser Token Issuance
Langflow OSS - Superuser Token Issuance
Langflow OSS with default AUTO_LOGIN exposes `/api/v1/auto_login`, which returns a superuser access token to any unauthenticated request.
Template:
id: CVE-2026-9103
info:
name: Langflow OSS - Superuser Token Issuance
author: str4k3r
severity: critical
description: |
Langflow OSS with default AUTO_LOGIN exposes `/api/v1/auto_login`, which returns a superuser access token to any unauthenticated request.
impact: |
An unauthenticated attacker obtains a superuser access token, granting full control of the Langflow instance including flow creation and execution, which typically leads to remote code execution and access to connected credentials and data sources.
remediation: |
Disable AUTO_LOGIN by setting `LANGFLOW_AUTO_LOGIN=false`, configure strong
No writeups or analysis indexed.
2026-07-17
Published