Insufficient Rate Limiting Vulnerability in LightRAG by HKUDS
CVE-2026-85734

9.1CRITICAL

Key Information:

Vendor

Hkuds

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-85734?

The login endpoint in LightRAG allows an attacker to perform unlimited authentication attempts without any rate limiting or locking mechanism. This oversight enables potential credential recovery through rapid guesswork, thereby granting unauthorized access to sensitive documents, knowledge graphs, and administrative features. This vulnerability was remedied in version 1.5.5, reinforcing security measures for user accounts.

Affected Version(s)

LightRAG < 1.5.5

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.