AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-86867.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSUnscoredNo severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSAwaiting NVD dataModified Sep 23, 2026

Disclosure summary

Overview Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can r

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

CERT Recently Published Vulnerability Notes · RSS-1e2d6979fad23b8dec051c07da03584c798

Open original source · Updated Sep 23, 2026

VU#754548: Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers

CVE mention in publisher metadata; check the original affected versions.

Original records & references

PUBLISHED 2026-09-23T13:41:05-04:00
MODIFIED 2026-09-23T13:41:05-04:00
INGESTED 2026-10-06T11:43:37-04:00