CVE-2026-7663
IBM Langflow OSS-Versionen von 1.0.0 bis 1.9.6 könnten es Angreifern ohne Authentifizierung ermöglichen, auf geschützte Ressourcen des MC… (CVE-2026-7663)
criticalEPSS 0.5 %
Beschreibung
IBM Langflow OSS-Versionen von 1.0.0 bis 1.9.6 könnten es Angreifern ohne Authentifizierung ermöglichen, auf geschützte Ressourcen des MCP-Projekts zuzugreifen und MCP-Operationen auszuführen, da die Autorisierungsüberprüfung im Streamable-MCP-Transportendpunkt nicht ordnungsgemäß durchgesetzt wird.
Metriken
Severity
critical
94.92
kein öffentlicher PoC bekannt
9.1
Veröffentlicht
2026-06-30 19:16 UTC
CWE-285
Weakness-Klassen (CWE)
CWE-285Class
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- Initial Analysis2026-07-02 18:19 UTC· nvd@nist.gov
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-863
- CPE Configuration: OR *cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* versions from (including) 1.0.0 up to (excluding) 1.10.0
- Reference Type: IBM Corporation: https://www.ibm.com/support/pages/node/7277570 Types: Vendor Advisory
- New CVE Received2026-06-30 20:17 UTC· psirt@us.ibm.com
- Affected: Langflow OSS
- Description: IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- CWE: CWE-285
- CVE Modified2026-06-30 20:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-7663","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…
Quellen & Referenzen
Verknüpfte Empfehlungen
IDCVE-2026-7663