Junglewise Threat Intelligence

CVE-2026-82281: Kotaemo authorization bypass in conversation management

CVE-2026-82281 · Severity: high · CVSS 7.4 · Published 2026-08-28

Executive brief

Kotaemo is an open-source RAG (retrieval-augmented generation) tool for chatting with documents. The application fails to properly validate whether users own conversations before allowing them to read, modify, or delete them, allowing attackers to access other users' chat histories, delete conversations, or rename conversations using arbitrary conversation identifiers.

Technical details

This is an authorization bypass (broken access control) vulnerability in the select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. The root cause is insufficient ownership validation—the functions accept conversation identifiers from users without verifying that the requesting user owns the conversation before performing operations. An attacker can exploit this over the network by supplying arbitrary conversation IDs to read sensitive chat histories, delete other users' conversations, or modify conversation metadata without authentication checks. No special preconditions are known to be required beyond basic network access to the application. Patches may be available in later versions.

Affected products

  • Cinnamon Kotaemo through 0.12.0

Timeline

  • 2026-08-28: disclosed

References