# CVE-2026-82281

## Summary

- **CVE ID:** CVE-2026-82281
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-639
- **Published:** Aug 28, 2026
- **Last Modified:** Sep 3, 2026

## Description

Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.

## Affected Products

- Cinnamon — kotaemon (0)

## References

- [CNA](https://github.com/Cinnamon/kotaemon/issues/846)
- [CNA](https://github.com/Cinnamon/kotaemon)
- [CNA](https://github.com/Cinnamon/kotaemon/blob/9ad3e4e49aa35b8acddd235918a5d9753c1cfdf9/libs/ktem/ktem/pages/chat/control.py)
- [CNA](https://www.vulncheck.com/advisories/kotaemon-missing-ownership-check-in-conversation-functions)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 18.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._