LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-55255: Langflow Authorization Bypass Through User-Controlled Key Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 7, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 10, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-55255 to its Known Exploited Vulnerabilities catalog on Jul 7, 2026, with a federal patch deadline of Jul 10, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow…

Langflow contains an authorization bypass through user-controlled key vulnerability. An authenticated attacker can execute any flow that belongs to another user by supplying that user's flow identifier in requests to the application. This issue affects organizations running Langflow and can result in unauthorized execution of workflows and access to associated data or logic.

How it works

The weakness is categorized as CWE-639. An authenticated user supplies a flow identifier that belongs to another account. The application does not enforce ownership checks on that identifier, allowing the attacker to invoke the target flow.

Attackers abuse this by crafting requests that reference arbitrary flow IDs. No further details on exploitation mechanics are provided in the available information.

Am I affected? How to find it in your systems

Inventory all Langflow installations in your environment, including any self-hosted or cloud deployments. Review the vendor advisory to determine which versions or configurations require attention.

How to remediate

Apply the vendor-supplied update referenced in the official advisory. Confirm the exact patch or configuration change against the vendor documentation for your deployment.

If you can't patch immediately

Follow CISA guidance on applying mitigations per vendor instructions and BOD 26-04 requirements. Segment Langflow instances from other systems and limit network exposure.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to breaches. You can run a free exposure scan of your email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedLangflow · Langflow
WeaknessCWE-639
Added to CISA KEVJul 7, 2026
Federal patch deadlineJul 10, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities