CVE-2026-82281 UNKNOWN

CVE-2026-82281

Published: 2026-08-28

Description

Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…