CVE-2026-32715
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-preferences endpoints allow manager role access, while every other surface that touches the same settings is restricted to admin only. Because of this inconsistency, a manager can call the generic endpoints directly to read plaintext SQL database credentials and overwrite admin-only global settings such as the default system prompt and the Community Hub API key.
Published:Mar 13, 2026
Last Modified:Mar 23, 2026
EPS:Mar 13, 2026
EPSS Score:0.0003
CVSS Score:3.8
Affected Products
Vendor
Product
Action
Vendor
Mintplexlabs
Product
Anything-llm
Mintplexlabs
Anything-llm
Vendor
Mintplexlabs
Product
Anythingllm
Mintplexlabs
Anythingllm
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
