CVE-2026-7787: Unauthenticated Session History Access via Public Flow Execution
IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.
Other sources
Langflow OSS could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.9.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7787?
The severity of CVE-2026-7787 is rated as high with a score of 8.1.
What type of access does CVE-2026-7787 exploit?
CVE-2026-7787 exploits unauthenticated access to session history via insecure direct object references.
Who is affected by CVE-2026-7787?
CVE-2026-7787 affects users of IBM Langflow OSS versions 1.0.0 through 1.9.1.
How do I fix CVE-2026-7787?
To fix CVE-2026-7787, ensure that proper authentication and access controls are implemented to prevent unauthorized access.
What kind of information can be accessed due to CVE-2026-7787?
CVE-2026-7787 may allow an authenticated user to read or modify sensitive information.