LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-33053

CVE-2026-33053 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: March 20, 2026

Langflow - Broken Access Control

Published: March 20, 2026Updated: March 20, 2026Remote Exploitable

Overview

Langflow < 1.9.0 contains a broken access control vulnerability caused by delete_api_key_route() endpoint deleting API keys without verifying ownership, letting authenticated users delete others' API keys, exploit requires user authentication.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 2.0%(Probability of exploitation in next 30 days)

Impact

Authenticated users can delete API keys belonging to other users, leading to unauthorized access disruption.

Mitigation

Update to version 1.9.0 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 20, 2026

🟠 CVE-2026-33053 - High (8.8) Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accepts an api_key_id path parameter and deletes it with only a generic authentication check (get_curren... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33053/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 20, 2026

🟠 CVE-2026-33053 - High (8.8) Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accepts an api_key_id path parameter and deletes it with only a generic authentication check (get_curren... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-33053/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-33053
Severity
High
CVSS Score
8.8
Type
broken_access_control
Status
confirmed
EPSS
2.0%
Social Posts
2

CWE

  • CWE-639

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

2.0%Probability of exploitation in the next 30 days