← back
CVE-2026-7787

Unauthenticated Session History Access via Public Flow Execution

CVSS 7.5 HIGHEPSS 0.2%CWE-639
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
11 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
IBM · Langflow OSS

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →