Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-61808: LightRAG API: Unauthenticated Access to Critical Functions

CVE-2026-61808 · published 27 days ago
Summary

The LightRAG API server is open to the internet without password protection. This allows unauthorized users to access and modify sensitive data, and potentially disrupt the service. To fix this, update to version 1.5.5rc1 or later.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
hkuds lightrag < 1.5.5rc1
Original advisory text
LightRAG: Missing Authentication for Critical API Functions in Default Configuration
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or delete documents, modify the knowledge graph, cancel pipelines, clear caches, and consume LLM resources. This issue is mitigated in version 1.5.5rc1.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published7 Aug 2026
Updated30 Aug 2026
First seen7 Aug 2026
Sources
CVE-2026-61808 · MITRE
Monitor software like this
Free during beta