Multi-User Chat Interface Vulnerabilities in Cinnamon’s Kotaemon
CVE-2026-86867
Currently unrated
What is CVE-2026-86867?
Cinnamon's Kotaemon multi-user chat interface presents significant security risks due to inadequate authorization checks and flawed access controls. Specifically, multiple handler methods in the control.py file fail to verify whether the requesting user's ID matches the owner of the conversation. This oversight enables any authenticated user to access private chat transcripts, delete or rename conversations, and modify chat suggestions belonging to other users. The implications of this vulnerability raise severe concerns over user privacy and data integrity within the chat environment.
Affected Version(s)
Kotaemon 0.12.0
