CVE-2026-81268: Langflow is vulnerable to authentication bypass and insufficient session expiration
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.
Other sources
Langflow OSS could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.6
Event History
Frequently Asked Questions
Who is exposed to this issue?
IBM Langflow OSS versions 1.0.0 through 1.11.5 are affected. Exploitation requires remote authenticated access and an API key whose associated user has been deactivated.
What can an attacker do with a key that remains valid after user deactivation?
The attacker could execute flows and obtain sensitive information. The issue is caused by API keys not expiring sufficiently after the associated user is deactivated.