Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 9 min 126 bronnen 1 kritiek 2 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-9103

CRITICAL · 9.8 CVSS Gepubliceerd: CWE-306

Beschrijving NL

IBM Langflow Oss 1.0.0 tot 1.10.0 kan een externe aanvaller in staat stellen om ongeautoriseerde toegang te krijgen als gevolg van onjuiste authenticatie in het /api/v1/login/auto_login-eindpunt. Het eindpunt geeft langlevende superuser bearer-tokens uit zonder authenticatie te vereisen wanneer de configuratie AUTO_LOGIN is ingeschakeld (standaard ingeschakeld), waardoor een niet-geverifieerde netwerkaanvaller volledige beheertoegang kan krijgen. Bovendien kunnen permissieve instellingen voor cross-origin resource sharing (CORS) tokens blootstellen aan onbedoelde oorsprong, waardoor het risico op ongeoorloofde toegang toeneemt.

Origineel (Engels) tonen

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabled (enabled by default), which may allow an unauthenticated network attacker to obtain full administrative access. Additionally, permissive cross-origin resource sharing (CORS) settings may allow tokens to be exposed to unintended origins, increasing the risk of unauthorized access.

Vendors

Langflow Apple Linux Microsoft

Affected products

Langflow Macos Linux Kernel Windows

References