CVE-2026-54036 | danny-avila LibreChat up to 0.8.4 /api/auth/2fa/enable missing authentication
A vulnerability was found in danny-avila LibreChat and classified as critical. The impacted element is an unknown function of the file /api/auth/2fa/enable. Executing a manipulation can lead to missing authentication.
This vulnerability is registered as CVE-2026-54036. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More