CVE-2026-7663: Unauthenticated Cross-User MCP Resource Access and Tool Execution via Streamable Transport Authorization Bypass
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
Other sources
Langflow OSS could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7663?
CVE-2026-7663 has a critical severity rating of 9.8.
How do I fix CVE-2026-7663?
To mitigate CVE-2026-7663, ensure you update IBM Langflow OSS to the latest version that addresses the vulnerability.
What are the risks associated with CVE-2026-7663?
CVE-2026-7663 allows unauthenticated attackers to access protected MCP resources and execute operations, significantly increasing the risk of data compromise.
What versions of IBM Langflow are affected by CVE-2026-7663?
CVE-2026-7663 affects IBM Langflow OSS versions from 1.0.0 to 1.9.6.
Is authentication required to exploit CVE-2026-7663?
No, CVE-2026-7663 can be exploited by unauthenticated attackers.