SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-18904

HIGH · CVSS 8.2 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-08

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.11.1 are vulnerable to a namespace collision issue that can be exploited by remote attackers to access sensitive information and inject unauthorized messages. Organizations using these versions should prioritize patching to mitigate the risk of data breaches and unauthorized communications. Immediate action is recommended for those handling sensitive data or operating in regulated environments.

CVE
CVE-2026-18904
Severity
HIGH
CVSS
8.2
EPSS
0.31%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.

Related CVEs

Other vulnerabilities affecting the same vendor(s)