CVE-2026-10140
Critical · CVSS 9.6IBM Langflow OSS — Insecure Direct Object Reference / Improper Authorization (CWE-639) — cross-tenant API client cache poisoning
- CVSS
- 9.6
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-639
Description
IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution.
Search profile — drives PoC discovery
Symbols voice modeAPI client cacheshared-statetenant boundaryupstream API credentialscache state manipulationcross-tenant billingaccountability misattribution
Keywords CVE-2026-10140IBM Langflow OSSLangflow voice modecross-tenant cacheshared state tenantAPI client reuseCWE-639 LangflowLangflow 1.0.0 1.10.0 vulnerabilityLangflow tenant credential leakLangflow billing misattribution PoC
Versions: 1.0.0 through 1.10.0
References
Status: enriched · ingested 2026-07-02T18:00:43.000Z · profiled 2026-07-02T18:30:43.000Z