CVE-2026-8446
Received Received - Intake

Authentication Bypass in IBM Langflow OSS via MCP Composer

Vulnerability report for CVE-2026-8446, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: IBM Corporation

Description

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth .

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm langflow From 1.0.0 (inc) to 1.10.3 (inc)
ibm langflow 1.11.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Langflow OSS versions 1.0.0 through 1.10.3 have an authentication bypass flaw in the Model Context Protocol (MCP) composer endpoint. This occurs when mcp_composer_enabled is set to true (default setting) and projects use OAuth authentication.

Detection Guidance

Check if IBM Langflow OSS versions 1.0.0 through 1.10.3 are running with mcp_composer_enabled=true and projects configured with auth_type=oauth. Inspect server logs for unauthorized access attempts to the MCP composer endpoint.

Impact Analysis

An attacker could exploit this to bypass authentication and gain unauthorized access to the MCP composer endpoint. This may allow them to manipulate project configurations or access sensitive data depending on the project's setup.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected versions may fail compliance audits due to insufficient access controls.

Mitigation Strategies

Disable the MCP composer endpoint by setting mcp_composer_enabled=false in the configuration. Change the auth_type from oauth to a more secure method if projects are configured with auth_type=oauth.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8446. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart