{"id":"CVE-2026-86867","title":"Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls","summary":"Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in `libs/ktem/ktem/pag…","severity":"none","cwe":["CWE-862","CWE-639","CWE-200"],"vendor":"Cinnamon AI","product":"Kotaemon","affected":["Kotaemon 0.12.0"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T19:19:42.080","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86867","references":[{"url":"https://kb.cert.org/vuls/id/754548","label":"cret@cert.org"},{"url":"https://www.kb.cert.org/vuls/id/754548","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-23T18:29:33.145Z","slug":"CVE-2026-86867","body":"## Overview\n\nCinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in `libs/ktem/ktem/pages/chat/control.py` that load a Conversation record by its ID without comparing the requester's `user_id` to the conversation's owner `Conversation.user`. This allows any authenticated user to perform the following actions:\r\n1. Read other user's chat transcripts, RAG retrieval history, AI-generated plots, and chat suggestions.\r\n2. Permanently delete another user's conversation.\r\n3. Rename another user's conversation.\r\n4. Overwrite another user's conversation's chat suggestion list.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}