Sysdig Blog
Read post

Understanding Langflow CVE-2026-55255, and why higher CVSS vulnerabilities aren't always the most exploited

The Sysdig Threat Research Team documented the first known in-the-wild exploitation of CVE-2026-55255, a CVSS 9.9 IDOR vulnerability in Langflow, observed alongside CVE-2026-33017, a CVSS 9.3 unauthenticated RCE. Despite its higher score, the IDOR received minimal attacker effort compared to the RCE, which has been exploited thousands of times. The analysis explains why: the RCE requires no authentication and is internet-sprayable, while the IDOR requires an authenticated session plus a disclosed flow UUID. The attacker's playbook involved enumerating flow IDs via an oversharing list endpoint, then replaying them with a 'leak api keys' prompt injection to steal credentials from other tenants' flows. The post argues that CVSS scores don't map directly to real-world exploitation likelihood — ease of exploitation and attacker effort-to-yield ratio matter more. It also highlights that in multi-tenant Langflow deployments, the IDOR is genuinely dangerous because it crosses tenant boundaries at the application layer without needing a sandbox escape.

    #security
Jun 26•10m read time•From webflow.sysdig.com
Post cover image
Table of contents
Understanding CVE-2026-55255 and how it's exploitedExploitation in the wildIDOR vs. RCE, and the key differences between CVE-2026-55255 and CVE-2026-33017What the Sysdig TRT observedThe attacker’s objective and motiveAutomation assessmentTimeline (UTC)Indicators of compromiseConclusion
151 Impressions
Sysdig Blog's image
Sysdig Blog

2 Followers

•

3 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard