CVE-2026-19875
Received Received - Intake

IBM Langflow OSS Email Overwrite Vulnerability

Vulnerability report for CVE-2026-19875, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: IBM Corporation

Description

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm langflow_oss From 1.0.0 (inc) to 1.10.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Langflow OSS versions 1.0.0 through 1.10.0 have an unauthenticated POST endpoint at /api/v2/registration/ that allows attackers to overwrite the admin email address without credentials. This can turn the Langflow instance into an outbound relay for email injection attacks.

Detection Guidance

Check if your Langflow OSS instance is running versions 1.0.0 through 1.10.0. Inspect network traffic for POST requests to /api/v2/registration/ without authentication. Monitor for unexpected admin email changes or outbound telemetry calls to external servers.

Impact Analysis

Attackers could enumerate valid email addresses, perform denial-of-service by relaying spam through your Langflow instance, or disrupt admin operations by overwriting registration data. The flaw enables unauthenticated abuse of the server as an email relay.

Compliance Impact

This vulnerability could lead to unauthorized email relay abuse, potentially violating data protection requirements under GDPR and HIPAA by enabling unauthorized data exfiltration or spam transmission through compromised systems.

Mitigation Strategies

Upgrade Langflow OSS to version 1.10.1 or later immediately. Block unauthenticated POST requests to /api/v2/registration/ at the network perimeter. Review admin email settings and outbound telemetry logs for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19875. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart