{"id":"CVE-2026-9198","title":"IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default L…","summary":"IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default L…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94"],"published":"2026-07-17","updated":"2026-07-18","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-9198","references":[{"url":"https://www.ibm.com/support/pages/node/7278927","label":"psirt@us.ibm.com"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.60597,"epssPercentile":0.9913,"ingestedAt":"2026-07-18T21:25:07.884Z","kev":true,"exploited":true,"kevDateAdded":"2026-08-04","kevDueDate":"2026-08-07","kevRansomware":false,"exploitAvailable":true,"exploits":{"exploitdb":true,"github":9,"githubRepos":["https://github.com/0xgh057r3c0n/CVE-2026-9198","https://github.com/0xdak/CVE-2026-9198_exploit","https://github.com/rmhowe425/PoC-CVE-2026-9198"],"metasploit":["exploit/multi/http/langflow_unauth_rce_cve_2026_9198"],"nuclei":["CVE-2026-9198"],"checkedAt":"2026-09-21T15:31:26.706Z"},"slug":"CVE-2026-9198","body":"## Overview\n\nIBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"hadal","depthScore":91,"depthScoreParts":{"impact":53.9,"likelihood":12.1,"exploitation":25,"ransomware":0},"changes":[{"seq":221,"id":"CVE-2026-9198","ts":1788469618997,"field":"exploit_available","old":"false","new":"true"},{"seq":220,"id":"CVE-2026-9198","ts":1788469618997,"field":"epss","old":"0.45213","new":"0.57019"},{"seq":217,"id":"CVE-2026-9198","ts":1788383023930,"field":"epss","old":"0.34734","new":"0.45213"},{"seq":187,"id":"CVE-2026-9198","ts":1787603691964,"field":"epss","old":"0.18784","new":"0.37327"},{"seq":117,"id":"CVE-2026-9198","ts":1785958688398,"field":"epss","old":"0.01886","new":"0.17053"},{"seq":114,"id":"CVE-2026-9198","ts":1785872131056,"field":"exploited","old":"false","new":"true"},{"seq":113,"id":"CVE-2026-9198","ts":1785872131056,"field":"kev","old":"false","new":"true"}]}