CVE-2026-61808Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or delete documents, modify the knowledge graph, cancel pipelines, clear caches, and consume LLM resources. This issue is mitigated in version 1.5.5rc1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-08-08); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-08: 1Mentions · 2026-08-10: 1Mentions · 2026-08-15: 1Patch / Workaround · 2026-08-10: 1Technical Details · 2026-08-08: 1Technical Details · 2026-08-10: 1Technical Details · 2026-08-15: 108-0808-1008-15
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-081
Disclosure1
2026-08-101
Patch1
2026-08-151
Disclosure1
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-61808 - high 🚨 LightRAG <= 1.5.4 - Missing Authentication > LightRAG through version 1.5.4 contains a broken access control vulnerability caused ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-61808 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2026-61808 is a high‑severity broken access control flaw in LightRAG 1.5.4 that stems from missing authentication; no PoC, exploit, or patch details are shared.

    00010281
    1.2K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-61808 - Critical unauthenticated access in LightRAG API server. Full data breach, doc manipulation, LLM abuse. CVSS 9.8. Upgrade to 1.5.5rc1 immediately. #CVE #LightRAG #infosec https://www.valtersit.com/cve/CVE-2026-61808 #infosec #cybersecurity #CVE #Linux #infosec #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu

    Post summary

    The message highlights a critical vulnerability in LightRAG and urges an immediate upgrade, but does not provide a PoC, exploit, or evidence of active attacks.

    0000087
    1.0K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🤖 LightRAG API flaw can expose entire AI knowledge bases A newly highlighted LightRAG vulnerability, CVE-2026-61808, leaves the API server reachable without authentication in its default configuration through version 1.5.4. Attackers could potentially read documents, modify the knowledge graph, delete data or consume LLM resources. 🔎 Source: GitHub Security Advisory / TheHackerWire #AISecurity #LightRAG #CVE #CyberSecurity #LLM

    Post summary

    The post announces a newly identified CVE for LightRAG, describing an unauthenticated API server and potential impact, but provides no PoC, exploitation tool, active exploitation claim or patch details.

    0000057
    34 followersView on X

Explore more