CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-9103Public Exploit

Langflow OSS - Authentication Bypass (CVE-2026-9103)

PublishedJul 17, 2026
First SeenOct 7, 2026
Last Seen
Reported
CVSS9.8
web_application

Description

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unintended origins, increasing the risk of unauthorized access.

psychologyCrowdSec Analysis

CVE-2026-9103 is a critical authentication bypass vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.0. When the default AUTO_LOGIN setting is enabled, unauthenticated remote attackers can obtain long-lived superuser bearer tokens through the auto-login endpoint and gain full administrative access, potentially leading to data theft, unauthorized changes, and service disruption. Permissive CORS configurations may further expose these tokens to unintended origins.

CrowdSec has been tracking this vulnerability and its exploits since 5th of October 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-9103 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers target the unauthenticated /api/v1/auto_login endpoint to obtain a response containing an access_token and a null refresh_token. This token can provide superuser-level access to the Langflow instance.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-07-17
Rule Released2026-10-05

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.