SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12766

MEDIUM · CVSS 5.4 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.11.2 are susceptible to server-side request forgery (SSRF), which could enable authenticated attackers to issue unauthorized requests from the server. This vulnerability may lead to network enumeration or serve as a stepping stone for further attacks. Organizations using affected versions should prioritize remediation to mitigate potential security risks.

CVE
CVE-2026-12766
Severity
MEDIUM
CVSS
5.4
EPSS
0.18%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.