AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-7658

MEDIUM · CVSS 6.5 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.10.3 are vulnerable due to improper validation of the username field, allowing attackers to exploit path traversal vulnerabilities. This can result in severe consequences such as arbitrary directory deletion, cross-tenant data destruction, and the deletion of JWT signing keys, which may invalidate user sessions. Organizations using affected versions should prioritize remediation to mitigate potential data breaches and service disruptions.

CVE
CVE-2026-7658
Severity
MEDIUM
CVSS
6.5
EPSS
0.34%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to session invalidation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)