AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-8446

HIGH · CVSS 7.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 through 1.10.3 are vulnerable to an authentication bypass through the Model Context Protocol (MCP) composer endpoint when the mcp_composer_enabled setting is true and projects use OAuth for authentication. This flaw could allow unauthorized access to sensitive data or functionalities, posing a significant risk to users relying on OAuth for secure access. Organizations utilizing affected versions should prioritize remediation to mitigate potential exploitation.

CVE
CVE-2026-8446
Severity
HIGH
CVSS
7.5
EPSS
0.28%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth .

Related CVEs

Other vulnerabilities affecting the same vendor(s)