Threat Intelligence / CVE / CVE-2026-7664

CVE-2026-7664

CVSS 9.8 (CRITICAL) · EPSS 0.3% · Priority 5.7/10 · Published 2026-06-22

As of 2026-06-23, CVE-2026-7664 is a CVSS 9.8 (CRITICAL-severity) vulnerability. EPSS exploitation probability 0.3%. Threadlinqs Intelligence tracks 0 threats exploiting it.

Last updated: 2026-06-23

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

CWE-287

References

Full detection coverage & IOCs for threats exploiting CVE-2026-7664 are available via the Threadlinqs MCP server (Purple tier). View plans →

← all vulnerabilities · Markdown version · Threadlinqs Intelligence

Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.