A vulnerability labeled as critical has been found in Mintplex-Labs AnythingLLM up to 1.15.0. Affected is the function
recoverAccount of the file server/utils/PasswordRecovery/index.js of the component Account Recovery. The manipulation of the argument recoveryCodes results in improper authentication.
This vulnerability is identified as CVE-2026-72917. The attack can be executed remotely. There is not any exploit available.