Executive brief
IBM Langflow is an open-source low-code platform for building AI applications with visual workflows. A flaw in the authorization controls on deprecated flow endpoints allows any authenticated user to access, execute, and read other users' private flows and embedded sensitive data. An attacker with login credentials can enumerate and manipulate flows belonging to other tenants without proper permission checks, compromising data confidentiality and workflow integrity.
Technical details
CVE-2026-19294 is an authorization bypass vulnerability (CWE-639) affecting Langflow OSS 1.0.0 through 1.11.1. The vulnerable deprecated build endpoints lack the object-level ownership validation present in modern equivalents, allowing any authenticated attacker to directly access other tenants' private flow components. The attack requires valid authentication credentials and network access to the Langflow API; no user interaction is needed. An attacker can enumerate and execute flows belonging to other users, extract embedded API keys and sensitive configuration values, and potentially manipulate workflows. IBM released a fix in version 1.11.2; upgrading immediately is the recommended remediation.
Affected products
- IBM Langflow OSS 1.0.0 through 1.11.1
Timeline
- 2026-08-28: disclosed
- 2026-08-21: patched: Version 1.11.2 released with fix