The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
SOONSTARTING SOONMicrosoft Windows & Surface EventIN 2HOpen coverage →
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Verified against the NVD record for CVE-2026-104335 (IBM PSIRT CNA, received 2026-10-07 00:17 UTC) and IBM security bulletin node/7290694 (initial publish 2026-10-02): product Langflow OSS, versions 1.0.0-1.12.2, remote authenticated code execution, CWE-284, CVSS 3.1 8.8 HIGH, fix 1.12.3, no workarounds. Earlier hold was a false positive: tweet word "Vendor" read as a product, and the CVSS vector string alone tripped the copy lint.

Sourcing
1source

via NVD

NVD · track record
39Stories
100%Verified
2030d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/IBM Langflow OSS flaw CVE-2026-104335 lets logged-in attackers run code
VERIFIEDBy Xavier Rivera· ·1 min read

IBM Langflow OSS flaw CVE-2026-104335 lets logged-in attackers run code

CVE-2026-104335 lets an authenticated remote attacker run arbitrary code on IBM Langflow OSS 1.0.0 through 1.12.2 because of improper access control. IBM rates it 8.8 (high) and says to upgrade to 1.12.3.

Source:NVD
Post
IBM Langflow OSS flaw CVE-2026-104335 lets logged-in attackers run code
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

CVE-2026-104335 affects IBM Langflow OSS 1.0.0 through 1.12.2. A remote attacker with a low-privilege account can run arbitrary code because of an improper access control weakness. IBM scores it 8.8 out of 10 and recommends upgrading to version 1.12.3; it lists no workarounds.

A newly listed vulnerability, CVE-2026-104335, lets a remote attacker who already holds an account run arbitrary code on servers running IBM Langflow OSS versions 1.0.0 through 1.12.2.

The cause is a broken access check.
IBM, which assigned the CVE, classifies the bug as improper access control (CWE-284).
IBM, which assigned the CVE, classifies the bug as improper access control (CWE-284). Its record does not name the affected component or endpoint.

IBM scores it 8.8 out of 10, high severity.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
IBM's scoring vector shows the flaw is reachable over the network with low attack complexity, needs only a low-privilege login and no action from a victim, and carries high impact to confidentiality, integrity and availability.
IBM strongly recommends upgrading to 1.12.3 and lists no workarounds or mitigations.
The fix is Langflow OSS 1.12.3.

The issue is one of 25 Langflow OSS vulnerabilities in an IBM security bulletin first published October 2. IBM strongly recommends upgrading to 1.12.3 and lists no workarounds or mitigations.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
NVD received the entry on the evening of October 6 and has not yet completed its own analysis. Neither IBM nor NVD reports attacks using the flaw.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
securityvulnerabilityibm
More fromNVD
  • NVD adds CVE-2014-125130 for CodeArt Google MP3 WordPress plugin

    Tech · 4d
  • Critical CVE-2026-94541 in WPMobile.App Plugin

    Tech · 5d
  • JetFormBuilder Plugin Hit by Stored XSS Flaw Through Version 3.6.5.4

    Tech · 5d
More inTech
  • Forza Horizon 6 Physical Edition Confirmed for PS5 in Early 2027

    Tech · 1h
  • SpaceX seeks $40B debt led by Apollo to buy Nvidia chips

    Tech · 9h
  • Marvell lifts 2028 revenue target to approximately $20B on AI connectivity

    Tech · 12h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    Critical Command Injection Flaw in IBM Guardium 12.2

    Version 12.2 of IBM Guardium Data Protection carries the critical CVE-2026-84436 flaw scoring 9.1 on CVSS. Command injection in the certificate export CLI lets a privileged user execute commands as root.

  • Tech· 

    NVD adds CVE-2014-125130 for CodeArt Google MP3 WordPress plugin

    NVD has published CVE-2014-125130 on a CVSS 7.5 unauthenticated file read issue in the CodeArt Google MP3 Audio Player WordPress plugin through version 1.0.11. Remote attackers can reach wp-config.php and further sensitive files to enable site compromise, with exploitation first noted in 2023.

  • Tech· 

    Critical CVE-2026-94541 in WPMobile.App Plugin

    The WPMobile.App WordPress plugin is vulnerable to authorization bypass through version 11.82, enabling unauthenticated attackers to steal password-reset URLs when the mail-to-push feature is enabled. The flaw carries a CVSS score of 9.8 and can result in full account takeover for arbitrary users including administrators.

  • Tech· 

    JetFormBuilder Plugin Hit by Stored XSS Flaw Through Version 3.6.5.4

    The JetFormBuilder WordPress plugin harbors a stored XSS issue through version 3.6.5.4 that permits unauthenticated script injection into post meta, which then executes via Select Field options.

  • Tech· 

    Ninja Forms File Uploads plugin vulnerable to CVSS 8.1 arbitrary file flaw

    Versions of the Ninja Forms - File Uploads plugin through 3.3.34 allow unauthenticated attackers to perform arbitrary file read, write, and deletion by abusing the Amazon S3 upload mechanism, with remote code execution possible when that feature is active.