# CVE-2024-0798

## Summary

- **CVE ID:** CVE-2024-0798
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-272
- **Published:** Feb 25, 2024
- **Last Modified:** Mar 13, 2026

## Description

A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'. Despite the intended restriction that prevents 'default' role users from deleting admin-uploaded documents, an attacker can exploit this vulnerability by sending a crafted DELETE request to the /api/system/remove-document endpoint. This vulnerability is due to improper access control checks, enabling unauthorized document deletion and potentially leading to loss of data integrity.

## Affected Products

- mintplex-labs — mintplex-labs/anything-llm (unspecified)

## References

- [CNA](https://huntr.com/bounties/607f03a0-ab4d-4905-b253-3d28bbbd363c)
- [CNA](https://github.com/mintplex-labs/anything-llm/commit/d5cde8b7c27a47ab45b05b441db16751537f1733)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.57%
- **EPSS Percentile:** 45.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._