A vulnerability labeled as critical has been found in Mintplex-Labs AnythingLLM up to 1.15.0. Affected is the function recoverAccount of the file server/utils/PasswordRecovery/index.js of the component Account Recovery. The manipulation of the argument recoveryCodes results in improper authentication.

This vulnerability is identified as CVE-2026-72917. The attack can be executed remotely. There is not any exploit available.