CVE-2026-7663

IBM Langflow OSS-Versionen von 1.0.0 bis 1.9.6 könnten es Angreifern ohne Authentifizierung ermöglichen, auf geschützte Ressourcen des MC… (CVE-2026-7663)

criticalEPSS 0.5 %

Beschreibung

IBM Langflow OSS-Versionen von 1.0.0 bis 1.9.6 könnten es Angreifern ohne Authentifizierung ermöglichen, auf geschützte Ressourcen des MCP-Projekts zuzugreifen und MCP-Operationen auszuführen, da die Autorisierungsüberprüfung im Streamable-MCP-Transportendpunkt nicht ordnungsgemäß durchgesetzt wird.

Quelle: CVELISTV5NVD

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.1
Quelle: nvd-v3
42.5 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.5 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-06-30 19:16 UTC
CWE-285

Weakness-Klassen (CWE)

  • CWE-285Class

    Improper Authorization

    The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-07-02 18:19 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-863
    • CPE Configuration: OR *cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* versions from (including) 1.0.0 up to (excluding) 1.10.0
    • Reference Type: IBM Corporation: https://www.ibm.com/support/pages/node/7277570 Types: Vendor Advisory
  2. New CVE Received2026-06-30 20:17 UTC· psirt@us.ibm.com
    • Affected: Langflow OSS
    • Description: IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
    • CWE: CWE-285
  3. CVE Modified2026-06-30 20:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-7663","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalI…

Quellen & Referenzen

Verknüpfte Empfehlungen

IDCVE-2026-7663