What is CVE-2026-12945?
IBM Langflow OSS versions 1.0.0 through 1.10.1 contain a vulnerability allowing authenticated users to access and manipulate other users' build jobs due to improper access control on log retrieval and unauthenticated build endpoints. This improper access control issue enables unauthorized access and manipulation of sensitive build data. Affected users should immediately update to the latest patched version.
Azərbaycanca: IBM Langflow OSS proqramının 1.0.0-dən 1.10.1-ə qədər versiyalarında autentifikasiya olunmuş istifadəçilərə digər istifadəçilərin build tapşırıqlarına giriş və manipulyasiya imkanı verən zəiflik aşkarlanıb. Bu problem log retrieval və autentifikasiya olunmamış build endpoint-lərindəki düzgün olmayan giriş nəzarətindən (improper access control) qaynaqlanır. İstifadəçilərə dərhal təsirlənən versiyaları yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: IBM
FAQ2
Which versions of IBM Langflow OSS are affected by CVE-2026-12945?
The vulnerability affects IBM Langflow OSS versions 1.0.0 through 1.10.1.
What can an authenticated user do by exploiting CVE-2026-12945?
An authenticated user can access and manipulate other users' build jobs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.