CVE-2026-55255
Summary
An authorisation bypass in Langflow, the low-code LLM application framework, added to CISA's Known Exploited Vulnerabilities catalog on 7 July 2026.
Details
This is the second Langflow flaw in the digest corpus, alongside the code-injection route CVE-2025-3248 that ENCFORGE ransomware used in the same month. An authorisation bypass on an AI tooling platform is a quieter problem than a remote code execution but a broader one: it reaches whatever the application can reach — model endpoints, API keys, prompt and vector stores, and any database the flow is wired to — without needing to run code. The recurring theme across both entries is that AI-adjacent tooling is being adopted faster than it is being put behind authentication, and that the KEV catalogue now reflects it.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-55255 |
| CVSS | 8.4 |
| Vendor / product | Langflow (IBM) |
| Reported in the digest | 2026-07-09 |
Related Pages
Sources: raw/digests/Cyber-Digest-2026-07-09.md