ibm langflow-oss CVE-2026-12763 is a vulnerability in IBM Langflow Oss
Published on September 14, 2026

Langflow is vulnerable to authentication bypass and insufficient session expiration
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-12763 can be exploited with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
NONE

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Products Associated with CVE-2026-12763

Want to know whenever a new CVE is published for IBM Langflow Oss? stack.watch will email you.

 

Affected Versions

IBM Langflow OSS: