CVE-2026-82281

Source
https://cve.org/CVERecord?id=CVE-2026-82281
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82281.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82281
Published
2026-08-28T16:19:01.076Z
Modified
2026-08-30T03:48:23.892243982Z
Severity
  • 9.1 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Kotaemon Missing Ownership Check in Conversation Functions
Details

Kotaemon through 0.12.0 fails to properly validate conversation ownership in selectconv, deleteconv, renameconv, and onsetpublicconversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82281.json",
    "cwe_ids": [
        "CWE-639"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/cinnamon/kotaemon

Affected ranges

Type
GIT
Repo
https://github.com/cinnamon/kotaemon
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.12.0"
        },
        {
            "fixed": "0.12.0"
        }
    ]
}

Affected versions

v0.*
v0.0.0
v0.1.0
v0.10.0
v0.10.1
v0.10.2
v0.10.3
v0.10.4
v0.10.5
v0.10.6
v0.10.7
v0.11.0
v0.11.1
v0.11.2
v0.11.3
v0.2.0
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.4.0
v0.4.1
v0.4.10
v0.4.11
v0.4.12
v0.4.13
v0.4.14
v0.4.15
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.4.8
v0.4.9
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.6.0
v0.6.1
v0.6.10
v0.6.11
v0.6.12
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.6.7
v0.6.8
v0.6.9
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.7.5
v0.7.6
v0.7.7
v0.7.8
v0.7.9
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.9.0
v0.9.1
v0.9.10
v0.9.11
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82281.json"