What is CVE-2026-55255?
CVE-2026-55255 is an authorization bypass vulnerability in Langflow where an authenticated attacker can execute any flow belonging to another user by specifying the victim's flow ID in a user-controlled key. This flaw allows unauthorized access to other users' resources by manipulating the flow ID parameter. Affected users should immediately update Langflow to the latest version and review access control mechanisms.
Azərbaycanca: Langflow platformasında aşkarlanan CVE-2026-55255 zəifliyi autentifikasiya olunmuş hücumçuya istifadəçi tərəfindən idarə olunan açar vasitəsilə digər istifadəçilərə məxsus iş axınlarını (flow) icra etməyə imkan verən avtorizasiya bypass problemidir. Bu zəiflik hücumçuya qurbanın flow ID-sini sorğuda göstərməklə onun resurslarına icazəsiz giriş imkanı yaradır. Təsirə məruz qalan istifadəçilər dərhal Langflow-u ən son versiyaya yeniləməli və giriş nəzarəti mexanizmlərini yoxlamalıdırlar.
Related CVEs
link basis: same weakness class CWE-863
FAQ1
What threat does CVE-2026-55255 pose in the Langflow platform?
CVE-2026-55255 is an authorization bypass vulnerability that allows an authenticated attacker to execute flows belonging to other users by specifying the victim's flow ID through a user-controlled key, enabling unauthorized access to their resources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.