CVE-2026-86867 | Cinnamon AI Kotaemon up to 0.12.0 Multi-User Chat Interface control.py user_id/Conversation.user authorization
A vulnerability was found in Cinnamon AI Kotaemon up to 0.12.0. It has been classified as critical. This vulnerability affects unknown code of the file libs/ktem/ktem/pages/chat/control.py of the component Multi-User Chat Interface. Performing a manipulation of the argument user_id/Conversation.user results in missing authorization.
This vulnerability is identified as CVE-2026-86867. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More