CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-7664

Critical · CVSS 9.8

IBM Langflow OSS — Improper Authorization / Authentication Bypass on MCP Transport Endpoint

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-287, NVD-CWE-noinfo

Description

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

Search profile — drives PoC discovery

Symbols Streamable MCP transport endpointMCP project resourcesMCP operationslangflowmcp/mcpstreamable_httpMCPStreamableHTTPMCP transportauthorization enforcement
Keywords CVE-2026-7664IBM Langflow OSSLangflow MCP authentication bypassLangflow unauthenticated MCPLangflow Streamable MCP transportLangflow improper authorizationLangflow MCP endpoint bypassLangflow 1.8.4 vulnerabilityLangflow PoCCWE-287 Langflow
Versions: 1.0.0 through 1.8.4

References

Status: enriched · ingested 2026-06-27T00:00:38.000Z · profiled 2026-07-01T18:30:14.000Z