What is CVE-2026-61808?
In LightRAG up to version 1.5.4, the API server binds to all network interfaces with authentication disabled by default. This allows an unauthenticated network attacker to read indexed document content, upload, or delete documents. It is recommended to immediately enable authentication in the server configuration.
Azərbaycanca: LightRAG 1.5.4 versiyasına qədər API server default olaraq autentifikasiyasız bütün şəbəkə interfeyslərinə bağlanır. Bu, autentifikasiya olunmamış şəbəkə təcavüzkarına indekslənmiş sənəd məzmununu oxumaq, sənəd yükləmək və ya silmək imkanı verir. Dərhal server konfiqurasiyasında autentifikasiyanı aktivləşdirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
Which versions of LightRAG are affected by CVE-2026-61808?
This vulnerability affects all versions of LightRAG up to version 1.5.4.
What actions can an attacker perform by exploiting CVE-2026-61808?
An unauthenticated network attacker can read indexed document content, upload, or delete documents.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.