Critical CVE-2026-9198, CVE-2026-0770, CVE-2026-55255, CVE-2026-42271, CVE-2026-59822, CVE-2026-72898, CVE-2026-49869, CVE-2026-64849, CVE-2025-62593, CVE-2026-48710 — CISA has added ten 2026 vulnerabilities in self-hosted AI, analytics and workflow platforms to its exploited list, most giving unauthenticated remote code execution. Fixed versions for Langflow, LiteLLM, Metabase, Kestra, MLflow, Ray and Starlette.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Tools that teams spin up quickly in Docker (Langflow, LiteLLM, Metabase, Kestra, MLflow, Ray) are being found on the internet and exploited, often with no login needed. Default Langflow installs hand out superuser tokens to anyone; Metabase's password-reset endpoint has a CVSS 10 SQL injection; Kestra's auth filter can be bypassed by ending a URL in /configs. Upgrade, and never expose these tools without authentication in front.
| Langflow | CVE-2026-9198 (auto-login + code validation → unauth RCE, through 1.10.0), CVE-2026-0770 (exec_globals RCE as root), CVE-2026-55255 (IDOR, < 1.9.1) |
|---|---|
| LiteLLM | CVE-2026-42271 (MCP test endpoints run commands, 1.74.2–1.83.6), CVE-2026-59822 (MCP auth bypass, < 1.84.0) |
| Metabase | CVE-2026-72898: unauthenticated SQL injection via /reset_password → admin. CVSS 10 |
| Kestra | CVE-2026-49869: suffix-match auth bypass → unauthenticated RCE. CVSS 10. Fixed 1.0.45 / 1.3.21 |
| MLflow / Ray / Starlette | CVE-2026-64849 (SSRF, 3.3.0–3.14.x), CVE-2025-62593 (browser DNS-rebinding RCE, < 2.52.0), CVE-2026-48710 (Host header path confusion, < 1.0.1) |
| Exploited? | Yes, all ten on CISA KEV between June and September 2026 |
These platforms are usually deployed fast, from a docker run in a README, often on a cloud VM with a public IP, and many ship with authentication off or minimal by default. They also tend to hold API keys for paid services (OpenAI, Anthropic, cloud accounts) and database credentials. Attackers scan for them specifically, either to steal those keys or to mine crypto on the server.
| Product | CVE | What it is | Upgrade to |
|---|---|---|---|
| Langflow | CVE-2026-9198 | /api/v1/auto_login mints superuser tokens for any caller; chained with /api/v1/validate/code (runs code via exec()) = unauthenticated RCE on default installs. 1.0.0–1.10.0. | Newer than 1.10.0 (see IBM advisory) |
| Langflow | CVE-2026-0770 | exec_globals on the validate endpoint → unauthenticated code execution as root. | 1.9.0+ |
| Langflow | CVE-2026-55255 | IDOR on /api/v1/responses: run another user’s flow. | 1.9.1+ |
| LiteLLM | CVE-2026-42271 | MCP “test connection” endpoints accept a stdio command and run it (authenticated). | 1.83.7+ |
| LiteLLM | CVE-2026-59822 | Fake Authorization header triggers an OAuth2 fallback that skips key validation on the MCP endpoint. | 1.84.0+ |
| Metabase | CVE-2026-72898 | SQL injection in /reset_password → admin, no login. CVSS 10. | x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, x.63.5 or later |
| Kestra OSS | CVE-2026-49869 | Auth filter allowlists any path ending in /configs → whole API without auth → RCE. | 1.0.45 / 1.3.21+ |
| MLflow | CVE-2026-64849 | Unauthenticated webhook test endpoint follows redirects → full-read SSRF (cloud metadata, internal services). | 3.15.0+ |
| Ray | CVE-2025-62593 | Dashboard/API guarded only by a User-Agent check → a malicious web page in Firefox/Safari can run code on a developer’s Ray via DNS rebinding. | 2.52.0+ |
| Starlette | CVE-2026-48710 | Host header rebuilds request.url, so path-based security checks in middleware see a different path than the router. Affects any FastAPI/Starlette app relying on request.url.path for auth. | 1.0.1+ |
# Which of these are running in Docker?
docker ps --format '{{.Image}}\t{{.Ports}}' | grep -iE 'langflow|litellm|metabase|kestra|mlflow|rayproject'
# Python environments
pip show langflow litellm mlflow ray starlette 2>/dev/null | grep -E '^(Name|Version)'
Metabase shows its version under Admin → Troubleshooting or at /api/session/properties (version.tag). Kestra shows it in the UI footer.
And the most important check: is it reachable from the internet? Look at the Ports column. Anything bound to 0.0.0.0 on a public host is exposed, regardless of firewall assumptions. Docker port publishing bypasses UFW by default.
# Docker Compose: bump the tag (avoid :latest pins that never re-pull), then
docker compose pull && docker compose up -d
# pip installs
pip install -U langflow litellm mlflow ray starlette
For Starlette, update the framework in every FastAPI app you deploy and rebuild the images. It’s a library, so it’s inside your containers, not on the host.
-p 127.0.0.1:7860:7860) and put an authenticating reverse proxy in front: Caddy with forward_auth to Authelia/Authentik, or a VPN. See our Caddy reverse proxy guide.LANGFLOW_AUTO_LOGIN=false and configure a superuser. Auto-login is what makes CVE-2026-9198 unauthenticated.LITELLM_MASTER_KEY and keep the admin UI off the internet.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.