CVE-2026-58473: Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and cal...

Added to the CISA Known Exploited Vulnerabilities catalog on 07 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.1.

Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and calling the settings endpoint, which performs no admin or superuser check. Attackers can redirect all L...

Required action: Review and patch if applicable to your AI infrastructure.