CVE-2026-82281 – Kotaemon

CVSS 7.4 IMPORTANT Zero Day – Immediate Deployment

“Weak conversation ownership checks can expose private chats and let attackers alter or delete other users’ conversations.”

Kotaemon through version 0.12.0 contains a High-severity authorization vulnerability in conversation management functions. CVE-2026-82281 allows an attacker to supply arbitrary conversation identifiers and access another user’s chat history, rename conversations, or delete them without proper ownership validation. The CVSS score is 7.4, which is High severity.

Public proof-of-concept material is available for the vulnerability.

Key Details

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
CWE Classification
CWE-639
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.