PatchSiren

IBM CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH IBM CVE published 2026-08-05

CVE-2026-9205

IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. The CVE record was published on 2026-08-05T19:17:49.193Z and has not been modified since then. This vulnerability has a CVSS score of 7.4 and is classified as HIGH severity. The vulnerability allows for potential unauthorized access and data breaches. Affected systems may be vulnerable to explo [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-9201

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T19:17:48.657Z and has not been modified since then. The vulnerability is a cryptographic weakness in IBM Langflow OSS 1.0.0 through 1.10.3, allowing authenticated attackers to execute arbitrary code due to a weakness in the custom component validation mechanism. When the optional hardening mode i [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-9196

IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to unintended code execution during Agentic Assistant validation due to improper handling of LLM-generated components. Authenticated attackers may execute code with backend privileges, potentially triggering side effects like outbound network access or data exfiltration. Users should assess their exposure, restrict execution privileges, and implement com [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-9130

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T19:17:46.797Z and has not been modified since then. IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The vulnerability affects multi-user deplo [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-8470

IBM Langflow OSS versions 1.0.0 through 1.10.3 are vulnerable due to their use of Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. This practice, influenced by the deterministic nature of the Mersenne Twister PRNG, enables attackers to reproduce encryption keys and subsequently decrypt stored API keys and authentication tokens. The vulne [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-8183

IBM Langflow OSS versions 1.0.0 through 1.10.3 are vulnerable to a directory traversal attack. An attacker could send a specially crafted URL request containing 'dot dot' sequences to view arbitrary files on the system. This vulnerability could allow a remote attacker to traverse directories on the system. Organizations should be aware of this vulnerability and take steps to mitigate it. Affected operator [truncated]

MEDIUM IBM CVE published 2026-08-05

CVE-2026-7869

IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and write files anywhere on the server's filesystem.

MEDIUM IBM CVE published 2026-08-05

CVE-2026-7658

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T19:17:43.580Z and has not been modified since then. IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected by a vulnerability allowing path traversal sequences. This could enable multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing k [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-17633

IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to code injection, allowing a remote authenticated attacker to execute arbitrary code. The CVE record was published on 2026-08-05T19:17:29.043Z and has not been modified since then. This vulnerability has a CVSS score of 8.5 and is classified as HIGH severity. Affected users should prioritize patching to prevent potential attacks.

HIGH IBM CVE published 2026-08-05

CVE-2026-17632

IBM Langflow OSS 1.0.0 through 1.10.3 contains a vulnerability that could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning. This issue affects organizations using these versions, requiring prompt attention to mitigate potential code execution risks. The CVE record was published on 2026-08-05T19:17:28.923Z and has n [truncated]

MEDIUM IBM CVE published 2026-08-05

CVE-2026-10547

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T19:17:19.847Z and has not been modified since then. IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-9081

IBM Langflow OSS 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. This vulnerability allows an attacker to make unauthorized requests on behalf of the server, potentially leading to sensitive information disclosure or other malicious activities. Organizations using IBM Langflow OSS should be aware of thi [truncated]

MEDIUM IBM CVE published 2026-08-05

CVE-2026-7657

IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected by a server-side request forgery (SSRF) vulnerability due to incomplete and ineffective SSRF protection enforcement. This vulnerability could allow attackers to perform unauthorized requests on behalf of the server, potentially leading to security breaches. Organizations using these versions should prioritize patching and review their SSRF protec [truncated]

MEDIUM IBM CVE published 2026-08-05

CVE-2026-10128

IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users to exploit a built-in Langflow component, potentially exposing sensitive secrets by reading arbitrary server environment variables, despite security controls intended to disable custom components. This vulnerability could lead to unauthorized access to sensitive information. Affected users should review and update their installations to prev [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-9077

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T17:16:57.510Z and has not been modified since then. CVE-2026-9077 affects IBM Langflow OSS 1.0.0 through 1.10.3, allowing remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system. The CVSS scor [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-8446

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth . This authentication bypass vulnerability allows unauthorized access to affected systems, potentially leading to data breaches or system compromise. The vulnerability affects IBM [truncated]

MEDIUM IBM CVE published 2026-08-05

CVE-2026-7646

IBM Langflow OSS versions 1.0.0 through 1.10.3 are vulnerable to a path traversal attack, allowing users to read arbitrary files from the server filesystem. This is achieved by sending a crafted MCP `resources/read` request with a URL-encoded path traversal sequence in the filename. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. It potentially exposes sensitive information such as the [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-17630

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T17:16:44.923Z and has not been modified since then. Organizations using IBM Langflow OSS 1.0.0 through 1.10.3 should be aware of this potential vulnerability and take steps to validate configuration parameters and review compensating controls for exposed systems while remediation is scheduled and [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-17623

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T17:16:44.663Z and has not been modified since then. IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected by a vulnerability that allows remote authenticated attackers to execute arbitrary commands due to improper validation of the command field in MCP server configurations. Organizations s [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-17617

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T17:16:44.543Z and has not been modified since then. This vulnerability affects IBM Application Gateway Operator 22.2 through 26.06, allowing for Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources. Organizations should review their inventory and [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-8400

IBM WebSphere Application Server 8.5, 9.0, and Liberty Continuous delivery are affected by a flaw in the ORB component of IBM SDK, Java Technology Edition. This vulnerability may allow a malicious IIOP server to induce loading and instantiation of arbitrary classes, potentially leading to high impact on confidentiality, integrity, and availability. Administrators and users, operators, and security teams s [truncated]

MEDIUM IBM CVE published 2026-08-05

CVE-2026-18531

IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret. This vulnerability affects session data integrity and confidentiality. Security teams should review official advisories for scope and severity. Evidence is limited; primary records indicate a weak HMAC session signing secret in these versions. Defen [truncated]

MEDIUM IBM CVE published 2026-08-05

CVE-2026-12762

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T16:16:49.600Z and has not been modified since then. This medium-severity vulnerability affects IBM Cloud Pak For Business Automation versions 24.0.0, 24.0.1, 25.0.0, and 26.0.0, potentially allowing remote attackers to obtain sensitive information exposed in manifest files. Organizations should r [truncated]

LOW IBM CVE published 2026-08-05

CVE-2026-12730

IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server. This issue arises in versions 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009. The vulnerability may impact IBM Business Automation Workflow administrator [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-10025

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use XML-format property autodetection, the system processes XML-formatted syslog events sent to por [truncated]

Known exploited IBM CVE published 2026-08-04

CVE-2026-9198

CVE-2026-9198 is a critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.0, allowing unauthenticated attackers to chain /api/v1/auto_login with /api/v1/validate/code to achieve full Remote Code Execution (RCE) on default Langflow deployments. This vulnerability enables attackers to mint SUPERUSER tokens and execute user code via exec(), leading to potential RCE attacks. Organizations shou [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-11536

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T20:16:52.140Z and has not been modified since then. The vulnerability affects IBM WebSphere Application Server 9.0 and 8.5, allowing for remote code execution. Organizations should prioritize patching due to the high CVSS score of 8.5. Evidence is limited to CVE and NVD details.

MEDIUM IBM CVE published 2026-07-30

CVE-2026-10569

IBM UCD and IBM DevOps Deploy are susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs due to inadequate log management. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Users and administrators should review log access controls an [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-12733

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T19:17:04.867Z and has not been modified since then. IBM DataPower Gateway is affected by a denial of service vulnerability due to improper resource limitations, classified as HIGH severity with a CVSS score of 7.5. Organizations should review official advisories, assess exposure, and prioritize p [truncated]

CRITICAL IBM CVE published 2026-07-30

CVE-2026-12118

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T19:17:04.483Z and has not been modified since then. The vulnerability affects IBM webMethods Integration (on prem) versions 10.15 and 10.11, allowing unauthenticated remote code execution due to deserialization of untrusted data. Organizations should prioritize patching or mitigating this vulnera [truncated]

MEDIUM IBM CVE published 2026-07-30

CVE-2026-10700

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T19:17:02.100Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API. The /api/v1/files/images/{flow_id}/{file_name} endpoint does not enforce authe [truncated]

MEDIUM IBM CVE published 2026-07-30

CVE-2026-10695

IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non-fenced federated queries. This issue arises from the server's handling of certain query types, which can lead to a denial of service condition. Security teams managing IBM Db2 federated servers should verify and apply patches to prevent potential denial of service attacks. Teams should review server config [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-10535

IBM Db2 is vulnerable to a buffer overflow in the setgid helper db2flacc. This issue affects IBM Db2 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4. The vulnerability could allow an attacker to execute arbitrary code with elevated privileges, potentially leading to significant operational impact. Security teams should review system configurations and prioritize patching. Evidence limits suggest focusing [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-12945

IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints. This vulnerability, classified as HIGH with a CVSS score of 7.1, affects deployments of IBM Langflow OSS within the specified version range. The vulnerability enables authenticated users to access and manipul [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-10842

IBM WebSphere Application Server 8.5, 9.0, and Liberty 17.0.0.3 through 26.0.0.7 are affected by a high-severity vulnerability allowing remote attackers to bypass security constraints. The vulnerability has a CVSS score of 7.5 and a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Organizations should review and apply patches or updates provided by IBM to address the vulnerability. Affected pr [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-14522

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2 and 12.0.1.0 through 12.0.12.27 are vulnerable to remote code execution due to improper neutralization of CRLF characters. This CVE record was published on 2026-07-30T15:16:25.693Z. Organizations should review the official CVE record and vendor advisory for affected scope, severity, and guidance. The vulnerability allows remote attackers to execute arbi [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-14519

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T15:16:25.547Z and has not been modified since then. The vulnerability affects IBM App Connect Enterprise versions 13.0.1.0 through 13.0.7.2 and 12.0.1.0 through 12.0.12.27, allowing remote attackers to read arbitrary files due to a path traversal vulnerability. This could lead to unauthorized acc [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-12947

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27, is vulnerable to sensitive information exposure. A local user could read log files containing potentially sensitive information. The CVE record was published on 2026-07-30T15:16:24.427Z and has not been modified since then. Users, administrators, and security teams should be aware of this vulnerability and take necessar [truncated]

HIGH IBM CVE published 2026-07-30

CVE-2026-11980

The IBM Aspera Desktop App versions 1.0.5 through 1.0.19 are vulnerable to arbitrary code execution due to loading DLL files at start-up. This vulnerability has a high CVSS score of 7.3, indicating a high severity vulnerability. Organizations should take immediate action to inventory and verify their installations, apply vendor remediation if available, and monitor for suspicious activity. The CVE record [truncated]

MEDIUM IBM CVE published 2026-07-30

CVE-2025-36298

The CVE-2025-36298 record details a cross-site scripting vulnerability in the Ebics server component of IBM Sterling B2B Integrator and IBM Sterling File Gateway. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI, potentially altering intended functionality and leading to credentials disclosure within a trusted session. Security teams should review the CVE re [truncated]

HIGH IBM CVE published 2026-07-28

CVE-2026-15328

IBM WebSphere Application Server 9.0, 8.5, and Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling. This vulnerability was published on 2026-07-28T21:17:27.920Z and has not been modified since then. The CVE record indicates that the vulnerability affects IBM WebSphere Application Server 9.0, 8.5, and Liberty 17.0.0.3 through 26.0.0.7. Users of these products should be aware of this v [truncated]

HIGH IBM CVE published 2026-07-28

CVE-2026-15325

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T21:17:27.770Z and has not been modified since then. The vulnerability affects IBM WebSphere Application Server 9.0, 8.5, and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7, allowing for HTTP request smuggling due to improper handling of TRACE requests. Organizations should b [truncated]

HIGH IBM CVE published 2026-07-28

CVE-2026-15280

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T21:17:27.640Z and has not been modified since then. CVE-2026-15280 is a HIGH-severity vulnerability in IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller. It is caused by a path-segment injection vulnerability in the collective routing mechanism. The CVS [truncated]

HIGH IBM CVE published 2026-07-28

CVE-2026-15064

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T21:17:27.493Z and has not been modified since then. IBM WebSphere Application Server 9.0, 8.5, and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens. This vulnerability has a [truncated]

HIGH IBM CVE published 2026-07-28

CVE-2026-15057

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T21:17:27.367Z and has not been modified since then. The vulnerability affects IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.7, allowing attackers to cause a denial of service due to uncontrolled heap allocation. This issue, classified as CWE-787, could disrupt servic [truncated]

HIGH IBM CVE published 2026-07-28

CVE-2026-14996

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T21:17:27.240Z and has not been modified since then. The vulnerability affects IBM Aspera Faspex 5, specifically versions 5.0.0 through 5.0.15.4, and is related to session management. This vulnerability has a CVSS score of 8.2 and is classified as HIGH severity. Users of IBM Aspera Faspex 5.0.0 th [truncated]

HIGH IBM CVE published 2026-07-28

CVE-2026-14981

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T21:17:27.090Z and has not been modified since then. The denial of service vulnerability in the HTTP channel of IBM WebSphere Application Server 9.0, 8.5, and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is due to unbounded allocation of resources without limits. This vulne [truncated]

HIGH IBM CVE published 2026-07-28

CVE-2026-14976

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T21:17:26.830Z and has not been modified since then. IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 are vulnerable to remote code execution when the collectiveController-1.0 feature is enabled. This feature's activation increases the attack surface, allowing potentia [truncated]

HIGH IBM CVE published 2026-07-28

CVE-2026-14974

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T21:17:26.700Z and has not been modified since then. This vulnerability, tracked as CVE-2026-14974, affects IBM WebSphere Application Server 8.5 and 9.0 traditional, allowing remote code execution due to unsafe deserialization of untrusted data. The CVSS score of 8.1 indicates high severity. Organ [truncated]

CRITICAL IBM CVE published 2026-07-28

CVE-2026-14959

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T21:17:26.443Z and has not been modified since then. The vulnerability affects IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4, allowing remote authenticated attackers to execute arbitrary code due to shell command injection. Organizations should prioritize patching due to the critical severit [truncated]