CyberRota Analysis
AI-GeneratedIBM Langflow OSS versions 1.0.0 to 1.10.0 are vulnerable to an authentication bypass, allowing authenticated attackers to read arbitrary files, including the JWT signing key. This can lead to the forging of authentication tokens, potentially compromising user accounts and sensitive data. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and data breaches.
CVE
CVE-2026-7872
Severity
HIGH
CVSS
7.5
EPSS
0.36%
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.
Related CVEs
Other vulnerabilities affecting the same vendor(s)