A vulnerability, which was classified as critical, has been found in HKUDS LightRAG up to 1.5.4. Affected by this vulnerability is an unknown functionality of the component API Server. The manipulation leads to improper authentication.

This vulnerability is documented as CVE-2026-61808. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.