Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Unrated

Improper Authorization in IBM Langflow OSS Streamable MCP Transport Endpoint

IdentifiersCVE-2026-7664CWE-285

CVE-2026-7664 is a critical improper authorization vulnerability in IBM Langflow OSS affecting versions 1.0.0 through 1.8.4. The flaw is in the Streamable MCP transport endpoint, where authorization enforcement is insufficient or absent. As a result, an unauthenticated remote attacker can access protected MCP project resources and invoke MCP operations that should require authorization. The issue is remotely exploitable over the network and does not require user interaction or prior authentication.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated attacker to bypass access controls on protected MCP project resources and execute MCP operations remotely. Based on the provided CVSS characteristics, the vulnerability can have high confidentiality, integrity, and availability impact, enabling unauthorized access to sensitive project data, unauthorized modification or execution of MCP-related actions, and potential disruption of affected services or workflows.

Mitigation

If you can’t patch tonight, do this now.

Until patching is completed, restrict network access to the Streamable MCP transport endpoint and to MCP project resources using firewall rules, reverse proxy access controls, VPN-only exposure, or other segmentation controls. Limit exposure of Langflow OSS instances to trusted administrative networks, monitor for unauthorized MCP operations, and review logs for anomalous unauthenticated access attempts against MCP-related endpoints.

Remediation

Patch, then assume compromise.

Upgrade IBM Langflow OSS to a vendor-fixed release that addresses CVE-2026-7664. The provided content indicates that versions 1.0.0 through 1.8.4 are affected, so organizations should apply the latest IBM/vendor security patches and move to a version newer than 1.8.4 if available from the vendor. Validate that the Streamable MCP transport endpoint enforces authentication and authorization correctly after patching.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity4

Community discussion across Reddit, Mastodon, and other social sources.