• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-9198: pre-auth remote code execution in IBM Langflow

Unauthenticated attackers can achieve full remote code execution against Langflow, impacting default deployments. CVE-2026-9198 allows network callers to chain API endpoints to mint SUPERUSER tokens and execute arbitrary code; the flaw affects Langflow versions 1.0.0 through 1.10.0. An attacker only needs network access to the Langflow service (no valid account or user interaction) to exploit this vulnerability.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.28658
CWE
CWE-94
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA added this CVE to the Known Exploited Vulnerabilities catalog with a federal remediation due date, and public exploit code exists; apply the vendor’s mitigations or patches and restrict internet exposure immediately.

What is CVE-2026-9198?

Unauthenticated attackers can achieve full remote code execution against Langflow, impacting default deployments. CVE-2026-9198 allows network callers to chain API endpoints to mint SUPERUSER tokens and execute arbitrary code; the flaw affects Langflow versions 1.0.0 through 1.10.0. An attacker only needs network access to the Langflow service (no valid account or user interaction) to exploit this vulnerability.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of IBM Langflow are affected?

BRANCHAFFECTEDFIXED
1.x1.0.0 – 1.10.0

Is CVE-2026-9198 being exploited?

CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on 2026-08-04, and U.S. federal agencies are required to remediate by 2026-08-07. Public exploit code is also available.

How to fix CVE-2026-9198

  1. Apply Langflow vendor mitigations or the vendor-supplied patch immediately following official instructions.
  2. Remove or block internet exposure to Langflow endpoints and restrict access to trusted networks only.
  3. Monitor Langflow logs and host telemetry for signs of unauthorized token issuance or code execution and investigate anomalies.
  4. If vendor mitigations are unavailable, discontinue use of exposed instances or isolate them until a fix is applied, per CISA guidance.

Frequently asked questions

Is CVE-2026-9198 being actively exploited?

Yes — CISA added CVE-2026-9198 to the Known Exploited Vulnerabilities catalog on 2026-08-04 and public exploit code is available.

Which Langflow versions are affected by CVE-2026-9198?

Langflow versions 1.0.0 through 1.10.0 are affected by CVE-2026-9198.

Is there a patch for CVE-2026-9198?

A patch or vendor mitigations are available according to the vendor status in the facts; follow Langflow vendor guidance and apply updates or mitigations immediately.

Does CVE-2026-9198 require authentication?

No, the vulnerability in Langflow can be exploited without authentication when the service is network-reachable.

References