CVE-2026-21445 – Missing authentication on critical API endpoints in Langflow
CVE-2026-21445 is a high-severity vulnerability in Langflow, an open-source tool for building and deploying AI agents and workflows. The vulnerability arises from missing authentication on critical API endpoints. The flaw allows unauthenticated remote actors to access functionality that requires a provable user identity or consumes significant resources; depending on deployment and which endpoints are exposed, this can lead to unauthorized actions, information disclosure, or execution of sensitive operations. Administrators should assume internet-exposed or multi-tenant instances are at elevated risk until patches are applied.
The IONIX research team developed a simulation to validate exposure to CVE-2026-21445. Confirmed findings are listed in this post.
References:
