First Published: 2026/01/16
Last Updated: 2026/01/16
Summary
An attacker with standard user access to Hybrid Manager can create a malicious MCP server definition that allows arbitrary code execution when the MCP server is used. If exploited, this vulnerability grants the attacker access to the Langflow pod as the Langflow user, which allows read and write access to all flows, variables, messages, and API keys for every user on the appliance. This includes credentials that are encrypted at rest because the encryption key is also available to the attacker.
Vulnerability details
CVE-ID: CVE-2026-6971
CVSS Base Score: 9.9
CVSS Temporal Score: Undefined
CVSS Environmental Score: Undefined
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products and versions
- Affected Product: Hybrid Manager (HM)
- Affected Versions: Innovation HM versions 2026.1 to 2026.5, inclusive.
Remediation/fixes
Remediation is available in HM 1.4.0.
References
Related information
Acknowledgement
Source: EDB
Change history
27 April 2026: Original Copy Published
Disclaimer
This document is provided on an "as is" basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information on the document is at your own risk. EDB reserves the right to change or update this document at any time. Customers are therefore recommended to always view the latest version of this document.