cvesecurityvulnerability
CVE-2026-72917: One Recovery Code Used Twice to Bypass AnythingLLM Account Recovery
AnythingLLM 1.0.0 through 1.15.0 lets a single recovery code satisfy the two-code check when submitted twice with different whitespace, enabling account takeover including admin accounts.