← Terug naar overzicht

CVE-2026-19286 affects IBM Langflow OSS versions 1.0.0 through 1.11.1. The vulnerability allows a remote attacker to execute arbitrary code on affected systems. The root cause is improper enforcement of security restrictions on the A2A (Agent-to-Agent) public endpoint. No authentication or special privileges appear to be required for exploitation, making this a high-severity remote code execution issue. IBM has published an advisory with remediation guidance. Organizations using affected versions of IBM Langflow OSS should apply patches or mitigations immediately. The vulnerability poses significant risk to environments where Langflow OSS is internet-accessible.

Affected products

  • IBM Langflow OSS 1.0.0 through 1.11.1

Related CVE's

  • CVE-2026-19286

Categories

  • Emerging Technologies
  • Enterprise Applications
  • Web Technologies