SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-8635

CRITICAL · CVSS 9.9 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.10.0 are vulnerable to a critical privilege escalation flaw that allows authenticated users to manipulate the database, execute arbitrary system commands, and potentially gain full control over the system. Organizations using these versions should prioritize immediate patching or mitigation strategies to prevent exploitation, as the impact could lead to complete system compromise.

CVE
CVE-2026-8635
Severity
CRITICAL
CVSS
9.9
EPSS
0.30%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)