{"id":"CVE-2026-58473","aliases":["GHSA-49f7-whx5-4256"],"url":"https://o3.security/vulnerability/CVE-2026-58473","summary":"Cognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settings","details":"Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and calling the settings endpoint, which performs no admin or superuser check. Attackers can redirect all LLM operations instance-wide to an attacker-controlled endpoint by exploiting the process-wide singleton configuration cache, enabling exfiltration of prompts, uploaded documents, extracted entities, and knowledge graph content from all users.","published":"2026-07-07T20:34:54.943Z","modified":"2026-09-03T20:40:33.263893075Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"cognee","fixedVersion":"1.5.0"}],"fix":{"url":"https://github.com/topoteretes/cognee/commit/d10b1b77e2157c6238fd4d1acb1923a048991699","label":"topoteretes/cognee@d10b1b7"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58473.json"},{"type":"ADVISORY","url":"https://github.com/topoteretes/cognee/releases/tag/v1.2.0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58473"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/cognee-unauthorized-llm-configuration-overwrite-via-api-v1-settings"},{"type":"FIX","url":"https://github.com/topoteretes/cognee/commit/d10b1b77e2157c6238fd4d1acb1923a048991699"},{"type":"PACKAGE","url":"https://github.com/topoteretes/cognee"},{"type":"EVIDENCE","url":"https://github.com/topoteretes/cognee/issues/3084"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T20:40:33.263893075Z"}}