CVE-2026-85693
Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-role Supabase client that bypasses row-level security and fails to validate file ownership, enabling attackers to retrieve indexed content chunks from victim files through crafted POST requests.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.25%
- CWE
- CWE-639
- Published
- 2026-09-04
- Last modified
- 2026-09-14
Affected products
- mckaywrigley chatbot-ui
Weakness type
Related vulnerabilities
- CVE-2026-16310 — MemberDash <= 1.8.5 - Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter
- CVE-2026-53552 — Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers
- CVE-2026-9812 — Missing property field ownership validation in Playbooks run property update endpoint
- CVE-2026-88877 — Traefik v3.7.0 Authentication Bypass via from-to-www-redirect
- CVE-2026-47156 — MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator
- CVE-2026-84148 — Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP System
- CVE-2026-82441 — Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys
- CVE-2026-82281 — Kotaemon Missing Ownership Check in Conversation Functions