CVE-2026-12763: Langflow is vulnerable to authentication bypass and insufficient session expiration
Published Sep 8, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.
Other sources
Langflow OSS could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component
— IBM
Affected Software
1 affected component
IBM Langflow OSS<=1.0.0-1.11.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.6
Event History
Sep 8, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 14, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments should be prioritized for review?
Prioritize IBM Langflow OSS deployments that use the MCP Tools component, where cache key isolation can allow access across user MCP server contexts.
2
What access does an attacker need to exploit this issue?
The attacker must be authenticated to Langflow OSS.