THREAT OPS › CVEs › CVE-2026-55255
CVE-2026-55255 — Langflow Authorization Bypass Through User-Controlled Key Vulnerability
Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
Vulnerability details
- Affected productsLangflow
- KEV remediation due2026-07-10
Exploiting threat actors
- TurlaG0010
Related reporting
- July 2026 CVE Landscaperecordedfuture
- [CISA KEV] CVE-2026-55255 — Langflow Langflow: Langflow Authorization Bypass Through User-Controlled Key Vulnerabilitycisa_kev
- 29th June – Threat Intelligence Reportcheckpoint_research
- 22nd June – Threat Intelligence Reportcheckpoint_research