SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19302

MEDIUM · CVSS 6.5 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 through 1.11.2 are vulnerable to improper validation of symbolic links, which could enable a remote authenticated attacker to access sensitive information. Organizations using these versions should prioritize remediation to mitigate the risk of data exposure. Security teams should assess their environments for affected versions and implement necessary updates or workarounds.

CVE
CVE-2026-19302
Severity
MEDIUM
CVSS
6.5
EPSS
0.49%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

Related CVEs

Other vulnerabilities affecting the same vendor(s)