CVE-2026-21445Active Exploitation(langflow / langflow)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for langflow langflow systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0.dev45, multiple critical API endpoints in Langflow are missing authentication controls. The issue allows any unauthenticated user to access sensitive user conversation data, transaction histories, and perform destructive operations including message deletion. This affects endpoints handling personal data and system operations that should require proper authorization. Version 1.7.0.dev45 contains a patch.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-26); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-26: 1Mentions · 2026-04-20: 1Mentions · 2026-06-10: 1PoC Mentioned / Linked · 2026-04-20: 1Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-06-10: 1Technical Details · 2026-04-20: 1Technical Details · 2026-06-10: 103-2604-2006-10
Signal classification2 categories
Active Exploitation
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-261
Disclosure1
2026-04-201
Active Exploitation1
2026-06-101
Active Exploitation1
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-21445 - critical 🚨 Langflow - Broken Access Control > Langflow is a tool for building and deploying AI-powered agents and workflows. Prior ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-21445 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces the new vulnerability CVE-2026-21445, a broken access control issue in Langflow, without providing any PoC, exploit, patch, or active exploitation details.

    00031186
    905 followersView on X
  • CrowdSec@Crowd_Security
    Active Exploitation

    🚨 In this week’s newsletter, we cover CVE-2026-21445, a Langflow authentication bypass now under active exploitation. We break down how PoCs turned into real attacks and what defenders should do next. Read the full analysis and protect your systems 👉 https://www.crowdsec.net/vulntracking-report/cve-2026-21445-langflow-authentication-bypass-exploitation https://t.co/QEf2Z1elQB

    Post summary

    The post announces CVE-2026-21445 as an authentication bypass in Langflow, highlights that it is currently being actively exploited, and notes that PoCs have evolved into real attacks, while directing readers to a full analysis.

    01011270
    19.5K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    AIアプリ開発向けオープンソースプラットフォーム「Langflow」の未修正脆弱性CVE-2026-5027が実際に悪用されていることが確認された。VulnCheckによると、この脆弱性はパストラバーサルの問題で、攻撃者が任意の場所へファイルを書き込める可能性がある。 この脆弱性はTenableが発見したもので、POST /api/v2/filesエンドポイントがアップロード時のfilenameパラメータを適切に検証していないことに起因する。攻撃者は「../」を含むパストラバーサル文字列を利用し、ファイルシステム上の任意の場所へファイルを書き込むことができる。 VulnCheckのCaitlin Condon氏によると、この問題はリモートコード実行につながる可能性がある。また、Langflowではデフォルト設定で認証不要の自動ログイン機能が有効になっているため、攻撃者は認証情報なしで脆弱なエンドポイントへ到達でき、単一のリクエストで有効なセッショントークンを取得できるという。 現在確認されている攻撃では、対象システムへテスト用ファイルを書き込む活動が行われている。Censysのデータによると、インターネット上には約7,000のLangflowインスタンスが公開されており、その多くは北米に存在する。 Langflowでは今年に入り、CVE-2026-0770、CVE-2026-33017、CVE-2026-21445、CVE-2025-34291など複数の脆弱性が攻撃対象となっている。記事によると、CVE-2025-34291はイラン系の国家支援グループ「MuddyWater」による悪用も確認されている。 https://thehackernews.com/2026/06/unpatched-langflow-flaw-cve-2026-5027.html

    Post summary

    The report confirms that CVE‑2026‑5027, a path‑traversal flaw in Langflow, is actively exploited in the wild, enabling attackers to write arbitrary files and potentially gain remote code execution, with no patch or workaround mentioned.

    000201.1K
    14.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more