CVE-2026-0558 | parisneo lollms up to 2.1.x Endpoint /api/files/extract-text get_current_active_user improper authentication (EUVD-2026-17035)
A vulnerability has been found in parisneo lollms up to 2.1.x and classified as critical. Affected is the function get_current_active_user of the file /api/files/extract-text of the component Endpoint. This manipulation causes improper authentication.
This vulnerability appears as CVE-2026-0558. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.