CVE-2026-82281
EUVD-2026-6781228.08.2026, 20:20
Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| cinnamon | kotaemon | 𝑥 ≤ 0.12.0 | CNA |
Common Weakness Enumeration
References