CVE-2026-7664
Undergoing Analysis
Undergoing Analysis - In Progress
Unauthenticated Access and MCP Operation Execution in IBM Langflow OSS
Publication date: 2026-06-22
Last updated on: 2026-06-22
Assigner: IBM Corporation
Description
Description
IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | langflow_oss | From 1.0.0 (inc) to 1.8.4 (inc) |
| ibm | langflow_oss | 1.9.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-287 | When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. |