CVE-2026-61808 is a critical missing-authentication vulnerability (CWE-306) in HKUDS LightRAG, a retrieval-augmented generation tool. By default the LightRAG API server binds to all network interfaces with authentication disabled, allowing an unauthenticated remote attacker to reach sensitive API endpoints. It carries a CVSS v3.1 base score of 9.8 (Critical).
