IBM Langflow OSS 1.01.9.6 Unchecked Auth Attempts Expose Accounts
CVE-2026-19297 Published on August 13, 2026

Insufficient Authentication Brute Force Protection on Login Endpoint
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-19297 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
NONE

Weakness Type

Improper Restriction of Excessive Authentication Attempts

The software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to brute force attacks.


Products Associated with CVE-2026-19297

Want to know whenever a new CVE is published for IBM Langflow Oss? stack.watch will email you.

 

Affected Versions

IBM Langflow OSS: