CVE-2026-82281
HIGH
NVD
CVSS Score
7.4
Severity
HIGH
Published
Aug 28, 2026
Vendor
unknown
Description
Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.