Skip to main content

VU#754548: Cinnamon's kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers

0
Critical
VulnerabilityCVE-2026-86867aicvecve-2026-86867cwe-862cwe-639cwe-200
Published: 09/23/2026 (09/23/2026, 17:44:52 UTC)
Source: CERT/CC

Description

Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in `libs/ktem/ktem/pages/chat/control.py` that load a Conversation record by its ID without comparing the requester's `user_id` to the conversation's owner `Conversation.user`. This allows any authenticated user to perform the following actions: 1. Read other user's chat transcripts, RAG retrieval history, AI-generated plots, and chat suggestions. 2. Permanently delete another user's conversation. 3. Rename another user's conversation. 4. Overwrite another user's conversation's chat suggestion list.

Affected software

GitHub Actionsmore threats →ai
cinnamon/kotaemon
pkg:github/cinnamon/kotaemon
Affected versions
<=0.12.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 17:45:07 UTC

Technical Analysis

Cinnamon's Kotaemon (all versions up to v0.12.0) fails to verify conversation ownership in its multi-user chat interface. The affected handlers (select_conv, delete_conv, rename_conv, persist_chat_suggestions) query conversations by ID without ensuring the conversation belongs to the requesting user. This allows any authenticated user to read full chat transcripts, retrieval histories containing verbatim excerpts from private documents, rename conversations, overwrite chat suggestions, or delete conversations permanently. Conversation UUIDs are exposed via the global conversation browser and remain valid even if conversations are later set to private. The persist_chat_suggestions handler can be abused to inject attacker-controlled prompts, potentially influencing the AI model. There is no recycle bin or soft-delete, so deletions are permanent. The vulnerability is an IDOR (Insecure Direct Object Reference) affecting confidentiality, integrity, and availability.

Potential Impact

The vulnerability allows disclosure of full chat transcripts and retrieval histories containing sensitive document excerpts, violating confidentiality. Attackers can permanently delete any conversation, impacting availability. Integrity is compromised by renaming conversations and injecting attacker-controlled prompt suggestions, which may influence AI behavior. No elevated privileges are required; any authenticated user can exploit this. The exposure of UUIDs through public conversation listings facilitates exploitation. The lack of soft-delete means deleted conversations cannot be recovered. This is particularly impactful in enterprise environments where proprietary documents are indexed and queried.

Mitigation Recommendations

No official patch or fix is currently available as the vendor could not be reached for coordination. Users should monitor the vendor's GitHub repository and official website for future updates and patches. Until a fix is released, restrict authenticated user access to trusted parties only and consider additional access controls or network segmentation to limit exposure. Review and audit conversation UUID exposure in public listings to reduce risk. Avoid using Kotaemon in multi-user mode in sensitive environments until the issue is resolved.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.63,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://kb.cert.org/vuls/id/754548","fetched":true,"fetchedAt":"2026-09-23T17:45:01.302Z","wordCount":753}

Threat ID: 6ab4101df7a7c541061cfecf

Added to database: 09/23/2026, 17:45:01 UTC

Last enriched: 09/23/2026, 17:45:07 UTC

Last updated: 09/24/2026, 04:12:48 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses