What is CVE-2026-8446?
This is an authentication bypass vulnerability in the MCP composer endpoint of IBM Langflow OSS versions 1.0.0 through 1.10.3, exploitable when mcp_composer_enabled is true and auth_type is set to oauth. Administrators should disable the composer endpoint or apply updates to mitigate the risk.
Azərbaycanca: IBM Langflow OSS-un 1.0.0-dən 1.10.3-ə qədər versiyalarında, MCP composer endpoint-də "auth_type=oauth" konfiqurasiyası aktiv olduqda yaranan authentication bypass zəifliyidir. Bu, təcavüzkara identifikasiyadan yan keçməyə imkan verir; administratorlar mcp_composer_enabled parametrini deaktiv etməli və ya versiyanı təcili yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: IBM
FAQ2
Which versions of IBM Langflow OSS are vulnerable to CVE-2026-8446?
IBM Langflow OSS versions 1.0.0 through 1.10.3 are vulnerable to this authentication bypass.
What should administrators do to mitigate CVE-2026-8446?
Administrators should disable the MCP composer endpoint or apply updates to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.