Vulnerability
Published 2026-08-04
Verified 2026-09-19
IBM Langflow unauthenticated code injection (CVE-2026-9198)
CISA lists CVE-2026-9198 as a Langflow code-injection issue that allows unauthenticated remote code execution on default deployments. Do not internet-expose unauthenticated AI workflow UIs. Apply vendor mitigations; this desk does not invent a patch build.
- Product
- IBM Langflow
- Exploited in Australia?
- unknown
Primary: NVD · Vendor: CISA KEV · CVE: CVE-2026-9198
