OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-85734

CRITICAL · CVSS 9.1 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The POST /login endpoint in LightRAG versions prior to 1.5.5 is vulnerable to brute-force attacks due to the absence of rate limiting and account lockout mechanisms, allowing attackers to rapidly submit password guesses. This critical vulnerability can lead to unauthorized access to sensitive documents and administrative functions if credentials are successfully compromised. Organizations using affected versions should prioritize upgrading to 1.5.5 to mitigate the risk of credential theft and potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85734
Severity
CRITICAL
CVSS
9.1
EPSS
0.36%

Original NVD Description

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication attempts. A network attacker can submit password guesses at full request speed until a valid account password is found. Successful credential recovery grants authenticated access to documents, the knowledge graph, and administrative operations. This issue is fixed in version 1.5.5.