Vulnerability
Published 2026-08-04
Verified 2026-09-19

IBM Langflow unauthenticated code injection (CVE-2026-9198)

CISA lists CVE-2026-9198 as a Langflow code-injection issue that allows unauthenticated remote code execution on default deployments. Do not internet-expose unauthenticated AI workflow UIs. Apply vendor mitigations; this desk does not invent a patch build.

Product
IBM Langflow
Exploited in Australia?
unknown

Primary: NVD · Vendor: CISA KEV · CVE: CVE-2026-9198

tech ai