CVE-2026-12945
Medium
Elevated severity or exploit probability.
CVSS base
7.1
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
EPSS — probability of exploitation (30 days)
0.2%
12.2th percentile
CISA KEV
Not listed
Weakness / dates
CWE-639
Published 2026-07-30 · modified 2026-08-04
CVSS breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
| Attack Vector | N | Network |
| Attack Complexity | L | Low |
| Privileges Required | L | Low |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | H | High |
| Integrity | N | None |
| Availability | L | Low |
Timeline
- 2026-07-30 — Published (NVD)
- 2026-08-04 — Last modified (NVD)
Description
IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.