PatchSiren

IBM CVE debriefs · Page 10

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL IBM CVE published 2026-07-17

CVE-2026-8505

IBM Langflow OSS 1.0.0 through 1.10.0 has a critical vulnerability in its webhook authentication logic, allowing unauthenticated users to trigger the execution of any flow when WEBHOOK_AUTH_ENABLE is set to False (the default setting). This could lead to Remote Code Execution (RCE) if an attacker knows a flow's UUID. The vulnerability has a CVSS score of 9.8 and is considered CRITICAL. Defenders of IBM La [truncated]

CRITICAL IBM CVE published 2026-07-17

CVE-2026-8481

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system commands with [truncated]

CRITICAL IBM CVE published 2026-07-17

CVE-2026-8476

CVE-2026-8476: IBM Langflow OSS Remote Code Execution Vulnerability. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validation, integrity verification, or authentication. This vulnerability allows for arbitrary code execution when malicious pickle payloads are processed. Users of IBM Langflow OSS 1.0.0 through 1.10.0 are affected by th [truncated]

HIGH IBM CVE published 2026-07-17

CVE-2026-8056

A critical security flaw exists in IBM Langflow OSS 1.0.0 through 1.10.0, allowing authenticated users to override component parameters at runtime via the API. The vulnerability is located in the parameter filtering mechanism within the `apply_tweaks()` function. This flaw could potentially allow attackers to modify component behavior, leading to unauthorized actions or data exposure. Users of IBM Langflo [truncated]

HIGH IBM CVE published 2026-07-17

CVE-2026-7872

IBM Langflow OSS 1.0.0 through 1.10.0 is vulnerable to an issue that allows an authenticated attacker to read arbitrary files, including the JWT signing key, and forge authentication tokens for any user. This vulnerability has a CVSS score of 7.5 and a severity of HIGH. Users of IBM Langflow OSS 1.0.0 through 1.10.0 should be aware of this vulnerability and take steps to mitigate it. The vulnerability is [truncated]

MEDIUM IBM CVE published 2026-07-17

CVE-2026-7771

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling specially crafted statements containing subqueries, which could lead to a denial of service. This vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. The vulnerability is caused by a trap in the database engine that can be triggered by maliciously crafted SQL statements. The affected products and ve [truncated]

HIGH IBM CVE published 2026-07-17

CVE-2026-7754

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 is vulnerable to server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism. This high-severity vulnerability could allow an attacker to perform SSRF attacks, potentially leading to unauthorized access or data breaches. Users of IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 [truncated]

HIGH IBM CVE published 2026-07-17

CVE-2026-7667

IBM Langflow OSS 1.0.0 through 1.10.0 is vulnerable to an arbitrary file write operation. An authenticated attacker can create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header, enabling file write operations with attacker-controlled content to any path accessible by the Langflow process. This vulnerability has a high impact on confidential [truncated]

LOW IBM CVE published 2026-07-17

CVE-2026-7364

IBM Verify Identity Access and IBM Security Verify Access are vulnerable to an open redirect attack, which could allow a remote attacker to conduct phishing attacks. The vulnerability affects IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1. An open redirect vulnerability allows attackers to redirect victims to arbitrary web sites.

MEDIUM IBM CVE published 2026-07-17

CVE-2026-4942

A medium-severity vulnerability was found in IBM i 7.6, 7.5, 7.4, and 7.3. The vulnerability allows a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled in the server configuration. This issue impacts IBM i users and administrators, who should review configurations and apply patches. The vulnerability has a medium CVSS score of 5.9.

MEDIUM IBM CVE published 2026-07-17

CVE-2026-4938

IBM Verify Identity Access and IBM Security Verify Access vulnerability CVE-2026-4938. An attacker with read-only privileges could make unauthorized modifications and deployments outside of their assigned permissions. This vulnerability affects IBM Verify Identity Access 11.0 through 11.0.2, IBM Security Verify Access 10.0 through 10.0.9.1, IBM Verify Identity Access Container 11.0 through 11.0.2, and IBM [truncated]

MEDIUM IBM CVE published 2026-07-17

CVE-2026-15995

IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 is vulnerable to a race condition in the Agentic AI assistant's concurrent request-handling logic. This could allow an attacker to obtain incorrect report summary results or cause report-processing failures when multiple authenticated users submit report-related tasks simultaneously. The vulnerability exists due to inadequa [truncated]

HIGH IBM CVE published 2026-07-17

CVE-2026-15322

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs. This vulnerability has a high severity with a CVSS score of 7.5. Users of these versions should be aware of this vulnerability and take necessary actions to protect their systems. The CVE record was published on 2026-07-17T20:17:15.800Z and has not bee [truncated]

MEDIUM IBM CVE published 2026-07-17

CVE-2026-15093

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 are vulnerable to a URL redirection attack due to improper validation of user-supplied URLs. A remote attacker could exploit this vulnerability to redirect users to malicious websites, potentially leading to phishing or other malicious activities. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. Users of IBM Engineering AI Hub 1 [truncated]

CRITICAL IBM CVE published 2026-07-17

CVE-2026-15091

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation. The vulnerability has a CVSS score of 9.3 and a severity of CRITICAL. This issue affects users of these product versions, who should review and apply necessary patches or updates provided by the vendor.

MEDIUM IBM CVE published 2026-07-17

CVE-2026-15069

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input during web page generation. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. This issue affects users of these product versions, who should apply patches to prevent script code execution.

MEDIUM IBM CVE published 2026-07-17

CVE-2026-14979

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of these products should apply vendor remediation to prevent potential denial of service attacks. The vulnerability affects the DOORS component, [truncated]

LOW IBM CVE published 2026-07-17

CVE-2026-14971

The CVE record for CVE-2026-14971 was published on 2026-07-17T20:17:15.190Z and has not been modified since then. IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs have a misconfiguration that may increase the attack surface and enable unintended or unauthorized operations under non-default conditions. This vulnerability has a CVSS score of 3.9, indicating a low severity [truncated]

MEDIUM IBM CVE published 2026-07-17

CVE-2026-14501

IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to the use of dangerous functions without sufficient restrictions. This vulnerability has a medium severity and a CVSS score of 4.3. Users should review the official CVE record and NVD details for further information. Affected product deployments should be identif [truncated]

HIGH IBM CVE published 2026-07-17

CVE-2026-14499

IBM Langflow OSS 1.0.0 through 1.10.1 Langflow is vulnerable to improper validation of user supplied input in the Python Interpreter component. This allows an authenticated user to execute arbitrary commands with elevated privileges on the system. The vulnerability has a CVSS score of 8.8 and is classified as HIGH. Users should review system configurations and take immediate action to protect their systems.

HIGH IBM CVE published 2026-07-17

CVE-2026-13473

IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. This vulnerability affects users of IBM Storage Protect Client within the specified versions. The issue has a high severi [truncated]

HIGH IBM CVE published 2026-07-17

CVE-2026-13448

IBM Langflow OSS 1.0.0 through 1.10.1 contains an unauthenticated remote code execution vulnerability in the public flow build endpoint (/api/v1/build_public_tmp/{flow_id}/flow). The vulnerability stems from an incomplete denylist in the validate_public_flow_no_code_execution() function that fails to block several code-execution agent components, including OpenDsStarAgent, CodeActAgentSmolagents, and CSVA [truncated]

HIGH IBM CVE published 2026-07-17

CVE-2026-9171

CVE-2026-9171 is a denial of service vulnerability in IBM PowerVM Novalink. A remote attacker could exploit this vulnerability by sending a specially-crafted request, causing the server to consume memory resources. This vulnerability has a CVSS score of 7.5 with a HIGH severity rating. IBM PowerVM Novalink users should review and apply patches to prevent denial of service attacks. The vulnerability is cau [truncated]

CRITICAL IBM CVE published 2026-07-17

CVE-2026-9135

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. This vulnerability allows authenticated users with flow creation privileges to execute arbitrary Python code on the backend, potentiall [truncated]

CRITICAL IBM CVE published 2026-07-17

CVE-2026-9103

A critical vulnerability was discovered in IBM Langflow OSS versions 1.0.0 through 1.10.0. The /api/v1/login/auto_login endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled by default, potentially allowing unauthenticated network attackers to gain full administrative access.

HIGH IBM CVE published 2026-07-17

CVE-2026-9762

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control. The CVE record was published on 2026-07-17T18:17:17.693Z and has not been modified since then. This vulnerability affects IBM Db2 products, allowing for potential remote code execution. Users should be aware of the vulnerability and take necessary actions to mitigate it.

CRITICAL IBM CVE published 2026-07-17

CVE-2026-9202

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance. When NEW_USER_IS_ACTIVE=true, newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing AUTO_LOGIN. This critical vulnerability affects users of Langflow OSS and requires immediate mitigation. Affected users should review deployment o [truncated]

CRITICAL IBM CVE published 2026-07-08

CVE-2026-9074

CVE-2026-9074 is a critical unauthenticated SQL injection vulnerability in IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3. The vulnerability allows attackers to inject malicious SQL code, potentially leading to data breaches and system compromise. This issue exists in the password reset functionality of IBM API Connect. Security teams and administrators should prioritize patching [truncated]

HIGH IBM CVE published 2026-07-08

CVE-2026-3144

IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update. This vulnerability has a high CVSS score of 8.1, indicating high severity. Users should check for updates and consider changing default credentials immediately. The vulnerability class is related to the use of defaul [truncated]

HIGH IBM CVE published 2026-06-30

CVE-2026-11541

IBM CICS Transaction Gateway for Multiplatforms and IBM WebSphere Application Server are affected by an HTTP request smuggling vulnerability. This vulnerability could allow attackers to smuggle HTTP requests, potentially leading to security breaches. IBM WebSphere Application Server administrators and users should review the official advisory and assess potential exposure.