# CVE-2026-9103: Langflow OSS - Authentication Bypass

> Live exploitation tracking for CVE-2026-9103 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-9103

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 9.8
- **Public exploit available:** Yes
- **Affected products:** IBM Langflow OSS
- **Weaknesses:** CWE-306 (Missing Authentication for Critical Function)
- **Tags:** web_application

## Description

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unintended origins, increasing the risk of unauthorized access.

## CrowdSec analysis

[CVE-2026-9103](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-9103) is a critical authentication bypass vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.0. When the default AUTO_LOGIN setting is enabled, unauthenticated remote attackers can obtain long-lived superuser bearer tokens through the auto-login endpoint and gain full administrative access, potentially leading to data theft, unauthorized changes, and service disruption. Permissive CORS configurations may further expose these tokens to unintended origins.

CrowdSec has been tracking this vulnerability and its exploits since 5th of October 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-9103 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting.
Additionally, according to week-over-week analysis by CrowdSec, exploitation of CVE-2026-9103 is surging. Attack volumes are spiking well above historical norms, indicating widespread and escalating interest from threat actors. CVE-2026-9103 is currently experiencing high visibility and active exploitation across the internet.

Attackers target the unauthenticated `/api/v1/auto_login` endpoint to obtain a response containing an `access_token` and a null `refresh_token`. This token can provide superuser-level access to the Langflow instance.

## Timeline

- 2026-07-17: CVE Published. CVE-2026-9103 is published to NVD.
- 2026-10-05: Rule Released. CrowdSec releases a rule to detect CVE-2026-9103 exploitation attempts against the CrowdSec Network.
- 2026-10-07: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-9103 for the first time.

## References

- https://www.ibm.com/support/pages/node/7278926
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-9103.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-9103) follows observed exploitation activity for CVE-2026-9103. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
