MEDIUMVulnerability

CVE-2026-82271

R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename conversations and append messages to other users' conversation histories, corrupting state and injecting malicious content.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-82271
signal_observed_at
2026-09-23T22:44:40+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
published_at
2026-08-28T20:20:17.950
last_modified
2026-09-23T17:17:45.983

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82271 — Ninja Signal Threat Intelligence | Ninja Signal