CVE-2026-82281 – Kotaemon
CVSS 7.4
IMPORTANT
Zero Day – Immediate Deployment
“Weak conversation ownership checks can expose private chats and let attackers alter or delete other users’ conversations.”
Kotaemon through version 0.12.0 contains a High-severity authorization vulnerability in conversation management functions. CVE-2026-82281 allows an attacker to supply arbitrary conversation identifiers and access another user’s chat history, rename conversations, or delete them without proper ownership validation. The CVSS score is 7.4, which is High severity.
Public proof-of-concept material is available for the vulnerability.
Key Details
- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-639
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.