PatchSiren cyber security CVE debrief
CVE-2026-8446 IBM CVE debrief
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth . This authentication bypass vulnerability allows unauthorized access to affected systems, potentially leading to data breaches or system compromise. The vulnerability affects IBM Langflow OSS users and administrators, as well as security teams and vulnerability management teams. They should verify affected versions and configurations, implement mitigations or patches as necessary, and review system configurations to ensure proper security controls are in place. Evidence from IBM and NVD indicates an authentication bypass vulnerability exists, but further investigation is needed to determine affected scope, vendor remediation, and potential mitigations.
- Vendor
- IBM
- Product
- Langflow OSS
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-05
- Original CVE updated
- 2026-08-05
- Advisory published
- 2026-08-05
- Advisory updated
- 2026-08-05
Who should care
IBM Langflow OSS users and administrators, as well as security teams and vulnerability management teams, should verify affected versions and configurations. They should implement mitigations or patches as necessary to prevent exploitation of the authentication bypass vulnerability. Additionally, operators and platform administrators should review system configurations and ensure that proper security controls are in place to mitigate potential impacts.
Technical summary
The Model Context Protocol (MCP) composer endpoint in IBM Langflow OSS 1.0.0 through 1.10.3 has an authentication bypass vulnerability when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth . This vulnerability allows unauthorized access to affected systems, potentially leading to data breaches or system compromise.
Defensive priority
High priority due to authentication bypass vulnerability
Recommended defensive actions
- Inventory and verify affected IBM Langflow OSS versions
- Check if projects are configured with auth_type=oauth and mcp_composer_enabled=true
- Implement compensating controls to mitigate authentication bypass
- Monitor for vendor remediation and apply patches
- Exception tracking and retest as necessary
Evidence notes
IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth . Evidence from IBM and NVD indicates an authentication bypass vulnerability exists. Further investigation is needed to determine affected scope, vendor remediation, and potential mitigations.
Official resources
-
CVE-2026-8446 CVE record
CVE.org
-
CVE-2026-8446 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T17:16:55.983Z and has not been modified since then.