CVE-2026-41487: Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, there is a role-based-access control flaw in the LLM connection update flow. An...

Added to the CISA Known Exploited Vulnerabilities catalog on 08 May 2026. Vendor: AI/ML. Product: LLM. CVSS score: 5.4.

Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, there is a role-based-access control flaw in the LLM connection update flow. An authenticated, low-privileged user of role “member” in a project could request the update of an exi...

Required action: Review and patch if applicable to your AI infrastructure.