SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12945

HIGH · CVSS 7.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.10.1 are vulnerable due to improper access control, allowing authenticated users to access and manipulate other users' build jobs via log retrieval and unauthenticated build endpoints. This can lead to unauthorized data exposure and potential disruption of build processes. Organizations using these versions should prioritize remediation to protect sensitive build information and maintain operational integrity.

CVE
CVE-2026-12945
Severity
HIGH
CVSS
7.1
EPSS
0.21%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.

Related CVEs

Other vulnerabilities affecting the same vendor(s)