{"id":"CVE-2026-82280","title":"Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier","summary":"Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite sy…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N","cwe":["CWE-639"],"published":"2026-08-28","updated":"2026-09-23","sourceUpdated":"2026-09-23T17:17:46.060","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82280","references":[{"url":"https://github.com/QuivrHQ/quivr","label":"disclosure@vulncheck.com"},{"url":"https://github.com/QuivrHQ/quivr/blob/v0.0.322/backend/api/quivr_api/modules/prompt/controller/prompt_routes.py","label":"disclosure@vulncheck.com"},{"url":"https://github.com/QuivrHQ/quivr/issues/3698","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/quivr-prompt-endpoints-missing-ownership-validation","label":"disclosure@vulncheck.com"},{"url":"https://github.com/The-Vibe-Company/Quivr/issues/3698","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00199,"epssPercentile":0.10057,"ingestedAt":"2026-09-23T17:28:14.815Z","slug":"CVE-2026-82280","body":"## Overview\n\nQuivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}