SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-9202

CRITICAL · CVSS 9.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.10.0 are vulnerable to unauthenticated account creation, allowing attackers to generate unlimited user accounts. If the deployment option NEW_USER_IS_ACTIVE is enabled, these accounts become immediately active, enabling unauthorized access to remote code execution endpoints without requiring additional authentication. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-9202
Severity
CRITICAL
CVSS
9.8
EPSS
0.28%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN.

Related CVEs

Other vulnerabilities affecting the same vendor(s)