CVE-2026-7664
Critical · CVSS 9.8IBM Langflow OSS — Improper Authorization / Authentication Bypass on MCP Transport Endpoint
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-287, NVD-CWE-noinfo
Description
IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
Search profile — drives PoC discovery
Symbols Streamable MCP transport endpointMCP project resourcesMCP operationslangflowmcp/mcpstreamable_httpMCPStreamableHTTPMCP transportauthorization enforcement
Keywords CVE-2026-7664IBM Langflow OSSLangflow MCP authentication bypassLangflow unauthenticated MCPLangflow Streamable MCP transportLangflow improper authorizationLangflow MCP endpoint bypassLangflow 1.8.4 vulnerabilityLangflow PoCCWE-287 Langflow
Versions: 1.0.0 through 1.8.4
References
Status: enriched · ingested 2026-06-27T00:00:38.000Z · profiled 2026-07-01T18:30:14.000Z