What is CVE-2026-10700?
CVE-2026-10700 is a broken access control vulnerability in IBM Langflow OSS versions 1.0.0 through 1.8.4, where the `/api/v1/files/images/{flow_id}/{file_name}` endpoint lacks authentication and authorization checks. This allows unauthenticated attackers to access arbitrary user files. Immediate patching or implementing strict access controls is strongly recommended.
Azərbaycanca: CVE-2026-10700: IBM Langflow OSS 1.0.0-1.8.4 versiyalarında `/api/v1/files/images/{flow_id}/{file_name}` endpointində autentifikasiya olmaması səbəbindən icazəsiz fayl əldə etməyə imkan verən broken access control zəifliyi aşkarlanıb. Bu, autentifikasiya olunmamış istifadəçilərə başqa istifadəçilərin fayllarına giriş imkanı yaradır. Təhlükəsizlik üçün dərhal versiyanı yeniləmək və ya giriş nəzarətlərini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: IBM
FAQ2
Which versions of IBM Langflow OSS are affected by CVE-2026-10700?
This broken access control vulnerability affects all versions of IBM Langflow OSS from 1.0.0 through 1.8.4.
What action can an unauthenticated attacker perform by exploiting CVE-2026-10700?
An unauthenticated attacker can access arbitrary files belonging to other users via the `/api/v1/files/images/{flow_id}/{file_name}` endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.