SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-19286

CRITICAL · CVSS 9.8 EPSS 0.62%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-08

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.11.1 are vulnerable to arbitrary code execution due to inadequate security restrictions on the A2A public endpoint. This critical vulnerability poses a significant risk, allowing remote attackers to exploit the flaw and potentially take control of affected systems. Organizations using these versions should prioritize immediate patching and mitigation efforts to safeguard their environments.

CVE
CVE-2026-19286
Severity
CRITICAL
CVSS
9.8
EPSS
0.62%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.

Related CVEs

Other vulnerabilities affecting the same vendor(s)