SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-81268

HIGH · CVSS 8.1 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.11.5 are vulnerable to remote authenticated attacks that exploit insufficient session expiration of API keys after user deactivation, potentially allowing attackers to execute flows and access sensitive information. Organizations using these versions should prioritize remediation to mitigate the risk of unauthorized access and data exposure. Immediate action is recommended for those managing sensitive data or relying on API integrations within their workflows.

CVE
CVE-2026-81268
Severity
HIGH
CVSS
8.1
EPSS
0.31%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.