CVE-2026-17627
Homebrew vulnerability analysis and mitigation

Overview

CVE-2026-17627 is an improper authorization vulnerability in IBM Langflow OSS that allows remote authenticated attackers to obtain sensitive information and inject messages into workflow history. It affects IBM Langflow OSS versions 1.0.0 through 1.10.2 (fixed in 1.10.3). The vulnerability was published on September 4, 2026, and is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). It carries a CVSS v3.1 base score of 7.1 (High) per NVD scoring, and 4.9 (Moderate) per the GitHub Advisory (GitHub Advisory, IBM Advisory).

Technical details

The root cause is an authorization bypass through user-controlled keys (CWE-639), where the application fails to properly validate that a user is authorized to access or modify records belonging to other users. An authenticated attacker with low privileges can manipulate key values in requests to access workflow history records or inject messages into them without proper authorization checks. The attack is conducted over the network and requires no user interaction, though it does require a valid (low-privileged) account (GitHub Advisory, IBM Advisory).

Impact

Successful exploitation allows a low-privileged authenticated attacker to access sensitive information they are not authorized to view and to inject unauthorized messages into workflow history records. This results in a high confidentiality impact (unauthorized data disclosure) and a low integrity impact (unauthorized data modification of workflow history), with no availability impact. The vulnerability could expose proprietary workflow data, AI pipeline configurations, or other sensitive operational information stored within Langflow instances (GitHub Advisory, IBM Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is approximately 0.177% (7th percentile), indicating a low near-term probability of exploitation. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Indicators of compromise

  • Logs: Unusual access patterns in application logs showing a low-privileged user repeatedly querying workflow history records belonging to other users or different tenants; unexpected write/inject operations to workflow history by accounts that should not have such permissions.
  • Application Behavior: Workflow history records containing messages or entries that do not correspond to legitimate user actions or expected workflow executions.
  • Network: Anomalous API requests targeting workflow history endpoints with manipulated record identifiers (e.g., sequential or enumerated IDs) from a single authenticated session.

Mitigation and workarounds

IBM has released a patch addressing this vulnerability; users should upgrade IBM Langflow OSS to version 1.10.3 or later. The fix is referenced in GitHub Advisory GHSA-g3x9-hm5j-gv7w and the IBM support page. As an interim measure, administrators should review workflow history logs for unauthorized access or message injections and restrict network access to Langflow instances to trusted users only (IBM Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-17627HIGH7.1
  • Homebrew logoHomebrew
  • langflow
NoYesSep 04, 2026
CVE-2026-17631MEDIUM6.5
  • Homebrew logoHomebrew
  • langflow
NoYesSep 04, 2026
CVE-2026-17622MEDIUM6.5
  • Homebrew logoHomebrew
  • langflow
NoYesSep 04, 2026
CVE-2026-14470MEDIUM6.5
  • Homebrew logoHomebrew
  • langflow
NoYesSep 04, 2026
CVE-2026-17621MEDIUM5.4
  • Homebrew logoHomebrew
  • langflow
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management