CVE-2026-17628: Langflow is affected by improper authentication due to missing password verification in the password reset endpoint
Published Sep 8, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication.
Other sources
Langflow OSS could allow a remote authenticated attacker to change the password of an account due to improper authentication.
— IBM
Affected Software
2 affected components
IBM Langflow OSS>=1.0.0<=1.10.2
IBM Langflow OSS<=1.0.0-1.10.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.3
Event History
Sep 8, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 14, 2026
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which versions are affected?
IBM Langflow OSS versions 1.0.0 through 1.10.2 are affected.
2
What access does an attacker need?
The attacker must be remotely authenticated to Langflow OSS. No user interaction is required.
3
What is the impact of successful exploitation?
A successful attacker could change an account password, affecting integrity and availability.