DIRAS TAKE
Urgent: public exploit code exists for this pre-auth RCE, so immediately remove or restrict external access to the A2A endpoint and apply the vendor remediation as soon as possible.
What is CVE-2026-19286?
An unauthenticated remote attacker can run arbitrary code on Langflow OSS by sending malicious requests to the publicly exposed A2A endpoint. CVE-2026-19286 affects Langflow OSS versions 1.0.0 through 1.11.1 and is caused by inadequate enforcement of server-side restrictions on that endpoint. An attacker only needs network access to the A2A endpoint; no user interaction or valid account is required.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of IBM Langflow OSS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.0.0 – 1.11.1 |
Is CVE-2026-19286 being exploited?
Public exploit code is available.
How to fix CVE-2026-19286
- Apply the vendor-provided patch or remediation as soon as it is installed or published.
- Block or restrict network access to the A2A public endpoint using firewall rules or an IP allowlist.
- Monitor Langflow OSS access logs and host telemetry for unusual requests to the A2A endpoint and signs of code execution or compromise.
- If compromise is suspected, isolate affected hosts and follow vendor incident response guidance while investigating.
Frequently asked questions
Is CVE-2026-19286 being actively exploited?
Public exploit code is available for CVE-2026-19286.
Which Langflow OSS versions are affected by CVE-2026-19286?
Langflow OSS versions 1.0.0 through 1.11.1 are reported affected.
Is there a patch for CVE-2026-19286?
Patch or remediation guidance has been made available by the vendor; deploy the vendor update or follow their mitigations promptly.
Does CVE-2026-19286 require authentication?
No, the vulnerability can be exploited without authentication via the A2A public endpoint.
References
- nvd.nist.gov/vuln/detail/CVE-2026-19286
- cve.org/CVERecord?id=CVE-2026-19286
- ibm.com/support/pages/node/7284733
- All IBM CVEs on CVE Radar
- CVEs published in September 2026