CVE-2026-82281
Kotaemon Missing Ownership Check in Conversation Functions
CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th
Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.
| CWE | CWE-639 |
| Vendor | cinnamon |
| Product | kotaemon |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for cinnamon kotaemon
Be the first to know when new high vulnerabilities affecting cinnamon kotaemon are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Cinnamon / kotaemon
0 โค 0.12.0
References
github.com: https://github.com/Cinnamon/kotaemon/issues/846 github.com: https://github.com/Cinnamon/kotaemon github.com: https://github.com/Cinnamon/kotaemon/blob/9ad3e4e49aa35b8acddd235918a5d9753c1cfdf9/libs/ktem/ktem/pages/chat/control.py vulncheck.com: https://www.vulncheck.com/advisories/kotaemon-missing-ownership-check-in-conversation-functions
Credits
๐ George Chen