CVE-2026-21445 is a broken access control / missing authentication vulnerability in Langflow, a platform for building and deploying AI-powered agents and workflows. In versions prior to 1.7.0.dev45, multiple critical monitoring API endpoints lacked required authentication checks, allowing remote unauthenticated access to functionality that should have been restricted to authorized users. Reported affected endpoints include /api/v1/monitor/messages, /api/v1/monitor/transactions, and /api/v1/monitor/messages/session/{session_id}. As a result, an unauthenticated attacker can retrieve sensitive user conversation data and transaction histories and invoke destructive actions such as deleting messages. The issue stems from missing authentication controls on critical FastAPI routes that should enforce user authentication before exposing personal data and system operations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2026-21445, targeting the Langflow product (versions prior to 1.5.1) on Microsoft Windows. The main exploit script, 'CVE-2026-21445.py', is heavily obfuscated using PyArmor, making the actual exploit logic unreadable. The repository includes the PyArmor runtime and a license file to enable execution of the obfuscated code. Documentation files (README.md, docs/description.md, docs/mitigation.md) clarify that the PoC is for academic and defensive research only, and provide mitigation advice (upgrade Langflow, restrict network exposure, enable authentication and TLS). The README and mitigation docs indicate the exploit likely targets a network-exposed service and may involve malformed BSON requests. The repository structure is typical for a PoC: a main exploit script, obfuscation runtime, license, documentation, and screenshots. No hardcoded network endpoints or IPs are visible due to obfuscation, but the attack vector is network-based. The exploit is not weaponized and is intended for controlled research environments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously exploited Langflow flaw mentioned only as background.
Another Langflow vulnerability referenced as having seen exploitation activity this year, but no further technical details are provided in the content.
Another Langflow vulnerability referenced as having seen similar targeting activity earlier in the year.
A critical broken access control vulnerability in Langflow that allows unauthenticated access to sensitive conversation and transaction data and permits destructive actions such as message deletion via exposed API endpoints.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.