User Ownership Vulnerability in R2R Messaging Platform
CVE-2026-82271
7.1HIGH
What is CVE-2026-82271?
The R2R messaging platform versions up to 3.6.5 contain a significant vulnerability due to inadequate validation of user ownership in conversation management processes. Authenticated users can exploit this flaw to alter conversations that do not belong to them, executing unwanted modifications. By submitting arbitrary conversation identifiers, an attacker can not only rename conversations but also append their own messages into the affected users’ conversation histories. This breach can lead to state corruption and the injection of malicious content, posing severe risks to user data integrity and privacy.
Affected Version(s)
R2R 0 <= 3.6.5
