CVE-2026-79725
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-284
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- IBM Langflow OSS
Weakness type
Related vulnerabilities
- CVE-2026-81941 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-81046 — Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure...
- CVE-2026-88864 — Capgo SSO Provider Authentication Bypass via PostgREST Direct Write
- CVE-2026-78084 — Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4
- CVE-2026-50165 — alf.io has Improper Access Control for Organization Owners that Exposes System Secrets
- CVE-2026-86774 — Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy
- CVE-2026-19625 — IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
- CVE-2026-75998 — ColdFusion | Improper Access Control (CWE-284)