SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12763

MEDIUM · CVSS 4.2 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.11.5 are vulnerable to improper cache key isolation in the MCP Tools component, enabling authenticated attackers to access another user's MCP server context. This could lead to unauthorized data exposure and potential manipulation of user-specific information. Organizations utilizing affected versions should prioritize remediation to mitigate risks associated with this vulnerability.

CVE
CVE-2026-12763
Severity
MEDIUM
CVSS
4.2
EPSS
0.15%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.