[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":44,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":51,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":57,"vulnerability-29732":64},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",["Island",45],{"key":46,"params":47,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":48},"{}",{"head":50},{},["Island",52],{"key":53,"params":54,"result":55},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":48},{"head":56},{},["Island",58],{"key":59,"params":60,"result":62},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":61},"{\"text-color\":\"gray\"}",{"head":63},{},{"id":65,"detectable_with":66,"vuln_details":72,"vuln_id":96,"name":97,"published":98,"updated":98},29732,{"tool":67,"engine":70},{"id":68,"name":69},1,"Network Scanner",{"id":68,"name":71},"Sniper",{"id":65,"codename":73,"description":74,"severity":75,"risk_description":76,"public_description":77,"public_recommendation":78,"recommendation":79,"references":80,"cvssv3":84,"epss_score":85,"epss_percentile":86,"cve":87,"in_cisa_catalog":89,"date":90,"software_type":91,"vendor":92,"product":93,"ptt_exploit_capabilities":94},null,"We found that the target IBM Langflow OSS server, version 1.0.0 through 1.10.0, is vulnerable to CVE-2026-9198, a remote code execution vulnerability (CWE-94) caused by chaining the \u002Fapi\u002Fv1\u002Fauto_login and \u002Fapi\u002Fv1\u002Fvalidate\u002Fcode endpoints. The \u002Fapi\u002Fv1\u002Fauto_login endpoint mints a SUPERUSER JWT for any unauthenticated network caller, and the \u002Fapi\u002Fv1\u002Fvalidate\u002Fcode endpoint executes attacker-supplied Python code via exec() when \"validating\" a function definition, since Python evaluates default-argument expressions at function-definition time. Chaining these lets an unauthenticated remote attacker obtain a privileged token and execute arbitrary commands on the server. Exploitation does not require user interaction. We have detected this by requesting a SUPERUSER access token from \u002Fapi\u002Fv1\u002Fauto_login, then submitting a code-validation payload to \u002Fapi\u002Fv1\u002Fvalidate\u002Fcode that executes the id command via a default-argument exec() call and reflects its output back in the HTTP response.","critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","IBM Langflow OSS, versions 1.0.0 through 1.10.0, is vulnerable to CVE-2026-9198, a remote code execution vulnerability caused by chaining the \u002Fapi\u002Fv1\u002Fauto_login and \u002Fapi\u002Fv1\u002Fvalidate\u002Fcode endpoints. The auto_login endpoint issues a privileged access token to any unauthenticated caller, which can then be used to execute arbitrary code on the server through the code-validation endpoint, leading to full remote code execution.","Update Langflow to a version later than 1.10.0.","We recommend updating IBM Langflow to a version later than 1.10.0 as provided by the vendor advisory, and ensuring AUTO_LOGIN is disabled in production deployments.",[81,82,83],"https:\u002F\u002Fwww.ibm.com\u002Fsupport\u002Fpages\u002Fnode\u002F7278927","https:\u002F\u002Fgithub.com\u002Fywh-jfellus\u002FCVE-2026-9198","https:\u002F\u002Fgithub.com\u002F0xdak\u002FCVE-2026-9198_exploit",9.8,0.60597,0.9913,[88],"CVE-2026-9198",true,"2026-07-17T00:00:00Z","AI Application Builder","IBM","Langflow",[95],"RCE","NETSCAN-SNIPER-CVE-2026-9198","IBM Langflow - Remote Code Execution","2026-09-08T00:00:00Z"]