IBMCVE-2026-12763
IBM Langflow OSS: missing authentication
Medium4.2CVE-2026-12763 · Published Sep 14, 2026 · updated Sep 16, 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Langflow OSS Product | >= 1.0.0, <= 1.11.5 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-306
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 14 | IBM MQ: information disclosure | Medium6.8 | No fix yet |
| Sep 14 | IBM Business Automation Workflow containers and traditional: XML external entity | High7.1 | No fix yet |
| Sep 14 | IBM Cloud Pak for Business Automation: missing authorization | Medium5.4 | No fix yet |
| Sep 14 | IBM Cloud Pak for Business Automation: denial of service | Medium6.5 | No fix yet |
| Sep 14 | IBM Langflow OSS: server-side request forgery | Critical9.6 | No fix yet |
| Sep 14 | IBM Sterling Secure Proxy: improper authorization | Medium4.3 | No fix yet |