IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7278209 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-06-30 20:17
Updated : 2026-08-11 23:17
NVD link : CVE-2026-10140
Mitre link : CVE-2026-10140
CVE.ORG link : CVE-2026-10140
JSON object : View
Products Affected
langflow
- langflow
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
