User Ownership Vulnerability in R2R Messaging Platform
CVE-2026-82271

7.1HIGH

Key Information:

Vendor

Sciphi-ai

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-82271?

The R2R messaging platform versions up to 3.6.5 contain a significant vulnerability due to inadequate validation of user ownership in conversation management processes. Authenticated users can exploit this flaw to alter conversations that do not belong to them, executing unwanted modifications. By submitting arbitrary conversation identifiers, an attacker can not only rename conversations but also append their own messages into the affected users’ conversation histories. This breach can lead to state corruption and the injection of malicious content, posing severe risks to user data integrity and privacy.

Affected Version(s)

R2R 0 <= 3.6.5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.