Langflow Authorization Bypass Through User-Controlled Key Vulnerability
July 31, 2026 · CISA · Severity: CRITICAL
Langflow, a software product, contains a critical vulnerability (CVE-2026-55255) that allows authenticated attackers to bypass authorization controls. By manipulating a user-controlled key in requests, attackers can execute flows belonging to other users by specifying the victim’s flow ID. This flaw was added to CISA’s Known Exploited Vulnerabilities catalog on July 7, 2026, and is actively being exploited in the wild. The vendor, Langflow, has not yet released a patch to address this issue. This vulnerability impacts organizations and individuals using Langflow, potentially exposing sensitive workflows and data to unauthorized access. The exploitation of this flaw could lead to data breaches, unauthorized actions, and compromised system integrity. Given its active exploitation, users are urged to monitor for suspicious activity and apply mitigations if available. This incident underscores the importance of robust authorization mechanisms and timely vulnerability patching in software products.
Key Takeaways
- CVE-2026-55255 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- The vulnerability involves privilege escalation or authentication bypass, granting unauthorized access to sensitive functions.
- CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
- Langflow Langflow: Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.