CVE-2026-4503
Unauthenticated Image Access in IBM Langflow Desktop
Publication date: 2026-04-30
Last updated on: 2026-04-30
Assigner: IBM Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | langflow_desktop | From 1.0.0 (inc) to 1.8.4 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-639 | The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in IBM Langflow Desktop versions 1.0.0 through 1.8.4. It allows an unauthenticated user to view images belonging to other users. This happens because of an indirect object reference issue, where a user-controlled key can be manipulated to access images that should not be accessible.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of sensitive or private images since an attacker does not need to authenticate to view other users' images. This can result in a loss of confidentiality and potentially harm user privacy.