2026-07-08HIGHexploitedLangflow IDOR (CVE-2026-55255) hits KEV; Sysdig shows one operator chaining it with the RCE CVE-2026-33017
Langflow cross-tenant IDOR (CWE-639), actively exploited, CISA KEV, chained with RCE CVE-2026-33017
cve · CVE-2026-55255
Coverage
1
first 2026-07-08 → last 2026-07-08
Latest activity
2026-07-08
Langflow IDOR (CVE-2026-55255) hits KEV; Sysdig shows one operator chaining it with the RCE CVE-2026-33017
Peak priority
high
1 high
Targets
technology
sectors: technology
Sources cited
2
2 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-55255, newest first. Check the date before acting on an older one.
- Upgrade every self-hosted Langflow to ≥ 1.9.1 now; rotate any LLM-provider or cloud credentials embedded in flows on instances that were internet-exposed.2026-07-08CVE-2026-55255 +1
- On multi-tenant/managed Langflow, additionally authorize or restrict the /api/v1/flows/ listing endpoint; the IDOR is inert without the UUID enumeration it provides.2026-07-08CVE-2026-55255 +1
Defender insights
What each entry about CVE-2026-55255 tells a defender to do, newest first.
Story timeline
Hunting pivots
Entries about Langflow cross-tenant IDOR (CWE-639), actively exploited, CISA KEV, chained with RCE CVE-2026-33017 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (50%)
- sysdig.com1 (50%)
External references
All cited sources (2)
- sysdig.comprimarySysdig Threat Research Teamhttps://www.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-prioritize-patching-langflow-auth-bypass-flaw/