Critical Vulnerability in IBM Langflow OSS: Unauthenticated User Account Creation
A critical vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts. When NEW_USER_IS_ACTIVE=true, these accounts can immediately authenticate and access RCE endpoints.
What happened
The vulnerability, tracked as CVE-2026-9202, affects IBM Langflow OSS versions 1.0.0 through 1.10.0. Unauthenticated attackers can exploit this flaw to create new user accounts on any Langflow instance. If the deployment option NEW_USER_IS_ACTIVE is set to true, these newly created accounts become active immediately, allowing attackers to authenticate and reach remote code execution (RCE) endpoints.
To mitigate this threat, it is recommended to upgrade to a version beyond 1.10.0 or set NEW_USER_IS_ACTIVE=false in your deployment options. Multiple independent sources have confirmed this vulnerability, including the NCSC and NIST's NVD, which have assigned critical severity ratings (CVSS 9.8 and above).
For more detailed information, consult the primary sources: NCSC-2026-0251 and the NIST NVD entries for CVE-2026-13446, CVE-2026-8476, CVE-2026-8481, CVE-2026-8505, CVE-2026-8635, CVE-2026-8859, CVE-2026-9103, CVE-2026-9135, CVE-2026-9198, and CVE-2026-9202.
How 0Day mitigates this
ibm langflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.