Multi-User Chat Interface Vulnerabilities in Cinnamon’s Kotaemon
CVE-2026-86867

Currently unrated

Key Information:

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-86867?

Cinnamon's Kotaemon multi-user chat interface presents significant security risks due to inadequate authorization checks and flawed access controls. Specifically, multiple handler methods in the control.py file fail to verify whether the requesting user's ID matches the owner of the conversation. This oversight enables any authenticated user to access private chat transcripts, delete or rename conversations, and modify chat suggestions belonging to other users. The implications of this vulnerability raise severe concerns over user privacy and data integrity within the chat environment.

Affected Version(s)

Kotaemon 0.12.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.