Unrated severityCISA KEVNVD Advisory· Published Jul 17, 2026· Updated Aug 4, 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
CVE-2026-9198
Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 1.0.0 - 1.10.0
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7278927mitrevendor-advisorypatch