← Back to search

CVE-2026-85734

9.1 CRITICALpublic exploit available

Published 2026-09-22 · Updated 2026-09-22

AI risk analysis

Summary
The LightRAG login endpoint lacks rate limiting, allowing attackers to perform brute-force password guessing attacks, which can lead to unauthorized access to sensitive documents and administrative operations.
Exploitability
Exploitation is relatively easy given full request speed access, requiring only network connectivity and knowledge of the endpoint.
Blast radius
If exploited, this can result in unauthorized access to sensitive data and administrative functions, potentially leading to significant data breaches.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 1.5.5 or later.
auth-bypassbrute-forceweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication attempts. A network attacker can submit password guesses at full request speed until a valid account password is found. Successful credential recovery grants authenticated access to documents, the knowledge graph, and administrative operations. This issue is fixed in version 1.5.5.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-307

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.