# CVE-2026-7664

> IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

- **CVSS:** 9.8 (CRITICAL)
- **EPSS:** 0.3%
- **CWE:** CWE-287

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-7664
Full threat coverage + IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
