SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-81211

HIGH · CVSS 8.8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.11.5 are vulnerable to arbitrary Python code execution by remote authenticated attackers, stemming from improper authorization of custom components in stored flows. This high-severity vulnerability poses a significant risk to any organization using these versions, as it could lead to unauthorized access and manipulation of sensitive data. Organizations utilizing IBM Langflow OSS should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-81211
Severity
HIGH
CVSS
8.8
EPSS
0.34%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.