CRITICAL 9.1 NVD

CVE-2026-82281

Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in

Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.

References

Published: 2026-08-28 · Source: NVD · Feed updated: 2026-08-28
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-08-28 via NVD.

Risk Timeline

CVE Disclosed2026-08-28 · -1 days ago

Remediation Resources

vulnfeed aggregates 11493 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.