CVE-2026-9198
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
- Published
- Jul 17, 2026
- Updated
- Aug 17, 2026
- Assigning CNA
- ibm
- Evidence observed
- Aug 4, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.1%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
Sources
10- CVE-2026-9198_exploitExploit
Unauthenticated RCE exploit for Langflow OSS chaining auto_login JWT bypass with validate/code exec() to achieve remote command execution and reverse shells.
- CVE-2026-9198Exploit
IBM Langflow Unauthenticated RCE via Auto-Login Bypass
- cve-2026-9198_exploitExploit
Exploit for CVE-2026-9198, containing proof-of-concept payloads and validation steps for assessing the vulnerability in target environments.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.