IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
Is CVE-2026-9198 exploited?
Listed in the CISA KEV catalog on 2026-08-04.
Federal remediation due 2026-08-07.
Past that date by 8 days.
EPSS puts exploitation in the next 30 days at 17%.
Public exploit code: none found in monitored sources.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2026-9198
PlainSec has not published a story about this CVE.