SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12946

CRITICAL · CVSS 9.9 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.10.0 are vulnerable to remote code injection due to inadequate input validation. This critical vulnerability could allow attackers to execute arbitrary code on affected systems, potentially leading to full system compromise. Organizations using these versions should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-12946
Severity
CRITICAL
CVSS
9.9
EPSS
0.35%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.

Related CVEs

Other vulnerabilities affecting the same vendor(s)