SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82271

MEDIUM · CVSS 6.5 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows authenticated users in R2R versions up to 3.6.5 to manipulate other users' conversations by bypassing ownership validation in conversation update and message handlers. This could lead to unauthorized modification of conversation content, including renaming conversations and injecting malicious messages, thereby compromising user data integrity. Organizations using affected versions should prioritize remediation to prevent potential data corruption and exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82271
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%

Original NVD Description

R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename conversations and append messages to other users' conversation histories, corrupting state and injecting malicious content.