MCPNews

The Model Context Protocol ecosystem, verified

Current spec 2026-07-28

Five MCP-related IBM Langflow OSS CVEs published to NVD, including an authentication bypass in the MCP composer endpoint

IBM's bulletin covering Langflow OSS MCP features was published 2026-07-31 and modified 2026-08-01, outside this window, but five of its CVEs reached NVD with a publication date of 2026-08-05. IBM marks five of the bulletin's seven CVEs as MCP-related. All CVSS numbers below are IBM's own.

IBM's bulletin "Security Bulletin: Langflow is affected by security vulnerabilities in Model Context Protocol features" was published 2026-07-31 and modified 2026-08-01. Five of its MCP-related CVEs reached NVD with a publication date of 2026-08-05.

CVE-2026-8446 is described by NVD as an authentication bypass in the MCP composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth, affecting Langflow OSS 1.0.0 through 1.10.3. IBM assigns CVSS 7.5 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), CWE-306. Four further MCP-related CVEs carry the same NVD publication date: CVE-2026-17623, CVE-2026-17626, CVE-2026-7646, and CVE-2026-9077. Their individual NVD records were not opened in the sweep; publication dates for those four come from the NVD API keyword response's published field.

Per IBM's bulletin, MCP-related scores are CVE-2026-17623 (8.8), CVE-2026-17626 (8.8), CVE-2026-8446 (7.5), CVE-2026-7646 (6.5), and CVE-2026-9077 (8.5). CVE-2026-17625 and CVE-2026-17630 are marked not MCP-related. Remediation: upgrade to Langflow OSS 1.11.0 or newer.

How was this verified, and what are the sources?

Published · last verified · confidence 0.90.

  1. NVD API record for CVE-2026-8446; published date, description quoted, IBM-assigned CVSS and CWE - accessed
  2. NVD API keyword query for MCP bounded to 2026-08-04 through 2026-08-07, 11 results with per-CVE published fields - accessed
  3. IBM security bulletin; dates, per-CVE CVSS with MCP-related marking, affected range and fix version - accessed

← All news