Sceawere
Vulnerability Detail
CVE-2026-19875UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM Langflow Registration Missing Authentication
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- IBM
- Product
- Langflow OSS
- Attack Type
- CWE-306 Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-19T18:16:36.557Z",
"pubdate": "2026-08-19T18:16:36.557Z",
"executiveSummary": "A missing authentication vulnerability exists in IBM Langflow OSS 1.0.0 through 1.10.0, specifically within the user registration mechanism. This security flaw allows unauthenticated remote attackers to interact directly with sensitive endpoint functionalities without requiring prior credentials or authorization.\nThe primary impact of this vulnerability involves the capability to overwrite critical administrator email configuration data and subsequently abuse the underlying server infrastructure to function as an unauthorized outbound email relay. Risk implications include potential system compromise, reputational damage, and operational disruption stemming from unauthorized message distribution via the affected host.\nAttackers require network connectivity to the target server exposing the vulnerable registration endpoint. Exploitation does not require prior authentication privileges or complex interaction, significantly lowering the barrier to entry for malicious actors seeking to leverage the host infrastructure for unauthorized mail relaying or administrative account manipulation.",
"technicalDetails": "The root cause of the vulnerability stems from an absence of proper authentication and access control enforcement on the registration endpoint within IBM Langflow OSS 1.0.0 through 1.10.0. Components responsible for handling user creation and administrative profile management fail to validate whether the requesting entity possesses legitimate authorization before processing state-modifying requests.\nExploitation occurs over the network via HTTP requests directed at the unprotected registration functionality. Because the endpoint lacks authentication checks, a remote attacker can transmit crafted payloads directly to the application server. The payload sequence bypasses standard authorization gates, enabling the adversary to manipulate internal application settings.\nThe step-by-step attack flow involves an unauthenticated remote attacker identifying the exposed registration endpoint on the target instance of IBM Langflow OSS. The attacker then constructs an HTTP request containing modified parameters designed to overwrite the existing administrator email address. Upon receiving the request, the vulnerable component processes the input without validation, successfully altering the administrative configuration.\nFollowing the successful overwrite of the administrator email information, the attacker can leverage the application server's built-in email functionality. By interacting with the compromised server, the actor abuses the system to relay outbound messages externally, utilizing the trusted server infrastructure to distribute unauthorized communications or phishing payloads.\nPrivilege requirements for this attack are nonexistent, as the vulnerability explicitly bypasses authentication checks. Network exposure is dependent on the accessibility of the Langflow server instance to the attacker, typically via standard web protocols. The post-exploitation impact includes persistent administrative control alteration and the misuse of server resources as an outbound relay."
}