CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-7663

Critical · CVSS 9.1

IBM Langflow OSS — Improper Authorization / Broken Access Control (unauthenticated access to protected MCP resources)

CVSS
9.1
nvd
EPSS
KEV
No
Class
other
CWE-285, CWE-863

Description

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

Search profile — drives PoC discovery

Symbols Streamable MCP transport endpointMCP project resourcesMCP operationslangflowmcp/mcpstreamable_mcpmcp_transportauthorizationunauthenticated
Keywords CVE-2026-7663IBM Langflow OSSLangflow MCPStreamable MCP transportunauthenticated MCPLangflow improper authorizationLangflow broken access controlLangflow MCP endpoint bypassLangflow 1.9.6 exploitCWE-285 LangflowCWE-863 Langflow
Versions: 1.0.0 through 1.9.6

References

Status: enriched · ingested 2026-07-03T00:00:43.000Z · profiled 2026-07-03T00:30:43.000Z