info: name: langflow author: A.I.G bot cve: CVE-2026-17628 severity: MEDIUM details: 'IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication (CWE-287). The vulnerability arises because the application fails to properly verify the identity of the user initiating a password change, enabling an authenticated attacker to modify the password of another user''s account and potentially take it over. Affected versions: 1.0.0 - 1.10.2. Fixed in version 1.10.3.' security_advise: Upgrade Langflow to version 1.10.3 or later. As a temporary mitigation, restrict access to the Langflow instance to trusted users only and monitor password-change activity for unauthorized modifications. cvss: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L summary: langflow improper authentication allows remote authenticated attacker to change another user's password rule: version >= "1.0.0" && version < "1.10.3" references: - https://www.ibm.com/support/pages/node/7286684