• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-55255: authenticated authorization bypass in Langflow Langflow

An authenticated user can execute flows belonging to other users on Langflow, allowing escalation of access and unauthorized workflow execution. CVE-2026-55255 is an authorization-bypass/IDOR issue that affects Langflow releases earlier than 1.9.1 as noted in vendor data; an attacker only needs a valid account and the target flow identifier to invoke the victim's flow. Network access is limited to whatever access a normal Langflow user has (no extra network privileges required).

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
8.4HIGH
EPSS
0.00887
CWE
CWE-639
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added this CVE to the Known Exploited Vulnerabilities catalog with a 2026-07-10 remediation requirement for federal agencies, so prioritize mitigations now and restrict internet exposure of Langflow instances until a vendor fix is installed.

What is CVE-2026-55255?

An authenticated user can execute flows belonging to other users on Langflow, allowing escalation of access and unauthorized workflow execution. CVE-2026-55255 is an authorization-bypass/IDOR issue that affects Langflow releases earlier than 1.9.1 as noted in vendor data; an attacker only needs a valid account and the target flow identifier to invoke the victim's flow. Network access is limited to whatever access a normal Langflow user has (no extra network privileges required). The weakness is classified as CWE-639 (Authorization Bypass Through User-Controlled Key).

Vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

Which versions of Langflow Langflow are affected?

BRANCHAFFECTEDFIXED
langflow< 1.9.1

Is CVE-2026-55255 being exploited?

CISA added CVE-2026-55255 to the Known Exploited Vulnerabilities catalog on 2026-07-07, and U.S. federal agencies must remediate by 2026-07-10. Public exploit code is available.

How to fix CVE-2026-55255

  1. Remove or restrict public internet access to Langflow instances and limit access to trusted networks.
  2. Apply vendor-provided mitigations and configuration guidance immediately, following CISA and vendor instructions.
  3. Monitor application logs and audit flow execution for unexpected runs and account abuse.
  4. Plan to apply the vendor patch as soon as a fixed release is published and verify integrity after updating.

Frequently asked questions

Is CVE-2026-55255 being actively exploited?

CISA added CVE-2026-55255 to its Known Exploited Vulnerabilities catalog on 2026-07-07 and U.S. federal agencies were required to remediate by 2026-07-10; public exploit code is also available.

Which Langflow versions are affected by CVE-2026-55255?

Langflow releases earlier than 1.9.1 are affected according to the vendor-provided affected range.

Is there a patch for CVE-2026-55255?

No vendor patch was listed as available as of 2026-09-29; follow vendor mitigations and monitoring guidance until a fixed release is published.

Does CVE-2026-55255 require authentication?

Yes. The vulnerability requires an authenticated Langflow account; an attacker can abuse a valid account plus a target flow identifier to execute another user's flow.

References