FastGPT NoSQL injection flaws allow authentication bypass and account takeover
FastGPT, an AI agent building platform, contained two NoSQL injection vulnerabilities (CVE-2026-40351 and CVE-2026-40352) in versions before 4.14.9.5. The login endpoint accepted MongoDB query operators as a password, letting unauthenticated attackers log in as any user including the root administrator, while the password change endpoint allowed bypassing old-password verification for full account takeover and persistence. Both were fixed in version 4.14.9.5.
Disclosed 17 April 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers could log in as any user, including the root administrator, and authenticated attackers could change passwords without knowing the current one, enabling full account takeover and persistence on affected FastGPT instances.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40351
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40352
