Pending AI Enrichment

This vulnerability was recently detected via the live feed and has not yet been processed by Precogs AI's context enrichment engine. The data below represents raw telemetric data.

RAW NVD TELEMETRY

CVE-2026-9225

CVSS Base Score
6.5 MEDIUM
Primary Weakness
CWE-639
Published Date
Sep 10, 2026
Data Source
NVD API

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api/v1/run/advanced/{flow_id} endpoint, the application allows component inputs to reference storage paths using arbitrary user or flow identifiers without verifying ownership. An attacker with low‑privileged authenticated access can supply a crafted file path pointing to another user’s storage namespace, causing the backend to read and return the contents of files uploaded by other users. This vulnerability bypasses intended authorization checks enforced by the file management API and may result in unauthorized disclosure of sensitive user data.

Related Vulnerabilitiesvia CWE-639

CVE-2026-339316.5 MEDIUM

IDOR in OpenEMR Patient Portal payment page before 8.0.0.3. Authenticated patients can access other patients' payment and billing data (PHI) by manipulating the 'recid' parameter.

CWE-639
CVE-2026-339344.3 MEDIUM

IDOR in OpenEMR Patient Portal 'show-signature.php' before 8.0.0.3. Authenticated patients can retrieve staff member signature images by supplying arbitrary user values in the POST body.

CWE-639
CVE-2026-340558.1 HIGH

IDOR in OpenEMR library/pnotes.inc.php before 8.0.0.3. Legacy patient notes functions fail to verify ownership, allows users to access and manipulate notes of unauthorized patients.

CWE-639
CVE-2026-334250 UNKNOWN

Discourse is an open-source discussion platform.

CWE-203CWE-639CWE-862
CVE-2026-330538.8 HIGH

Langflow is a tool for building and deploying AI-powered agents and workflows.

CWE-639
CVE-2026-321140 UNKNOWN

Discourse is an open-source discussion platform.

CWE-639

Is your system affected?

Precogs AI detects CVE-2026-9225 in compiled binaries, LLMs, and application layers — even without source code access.