Advisory · CVE-2026-104335
Authenticated remote code execution through Langflow access control failure
Langflow OSS releases 1.0.0 through 1.12.2 let a remote authenticated attacker execute arbitrary code through improper access control. IBM rates it high at CVSS 8.8.
- Vendor
- IBM
- Product
- Langflow OSS
- Identifier / CWE
- CVE-2026-104335
CWE-284 - Action timing
- Immediate
Explain it like I’m five
Langflow checks people's badges at the front door, but one back room trusts anyone already inside. A low-level visitor can walk into that room and press the big red button they were never supposed to reach.
- 01Authenticated access
A remote attacker authenticates to Langflow with valid, low-privilege credentials.
- 02Protected functionality
The attacker targets a function or resource that should be restricted beyond their privilege level.
- 03Access check gap
Improper access control fails to stop the request from reaching the protected code execution path.
- 04Arbitrary code runs
The attacker's code executes with the privileges of the Langflow service process.
What happened
IBM disclosed CVE-2026-104335 on October 7, 2026: an improper access control flaw in IBM Langflow OSS versions 1.0.0 through 1.12.2 that lets a remote authenticated attacker reach arbitrary code execution. IBM scores it high at CVSS 3.1 8.8; authentication is required but no user interaction beyond that.
Langflow deployments often expose login to broad groups: collaborators, demo users, or teams sharing one instance. Any of those accounts is enough here. The access control check that should fence off the code execution path does not hold, so an authenticated session can cross into functionality it was never meant to reach.
IBM’s bulletin lists no workarounds or mitigations for these Langflow flaws; it recommends addressing them by upgrading.
What to do
- Inventory every Langflow deployment and confirm the running version, paying attention to who holds accounts on shared instances.
- Upgrade affected instances (1.0.0 through 1.12.2) to the fixed release named in the IBM bulletin.
- Until patched, restrict network access to Langflow, review and prune accounts, and revoke sessions for accounts that no longer need access.
- Review application and system logs for unusual flow execution or code execution calls from low-privilege accounts.
- If exploitation cannot be excluded, rotate credentials held by or reachable from the Langflow host and review downstream systems.
Management note
Authentication as the only barrier means every account is a potential foothold, including stale demo and collaborator logins. Patching fixes the flaw, but an account review closes the class of exposure: treat both as the same task.