← Browse

CVE-2026-10140

Medium

Elevated severity or exploit probability.

CVSS base
9.6 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
EPSS — probability of exploitation (30 days)
0.4%
28.6th percentile
CISA KEV
Not listed
Weakness / dates
CWE-639
Published 2026-06-30 · modified 2026-08-11

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredLLow
User InteractionNNone
ScopeCChanged
ConfidentialityHHigh
IntegrityHHigh
AvailabilityNNone

Timeline

Description

IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution.

Affected

langflow

References

Official: NVD · CVE.org