CVE-2026-82271
Last modified
CVE-2026-82271 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename conversations and append messages to other users' conversation histories, corrupting state and injecting malicious content.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename conversations and append messages to other users' conversation histories, corrupting state and injecting malicious content.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| SciPhi-AI | R2R | <= 3.6.5 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-82271?
How severe is CVE-2026-82271?
How do I fix CVE-2026-82271?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82266Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 …9.8
- CVE-2026-82267Komodo through 2.3.2 discloses internal resource identifiers…5.4
- CVE-2026-82268Qwen-Agent through 0.0.34 contains a server-side request for…7.5
- CVE-2026-82269Gophish through 0.12.1 fails to enforce account lockout and …8.1
- CVE-2026-8227A weakness has been identified in Wavlink NU516U1 240425. Th…8.8
- CVE-2026-82270Portkey AI Gateway through 1.15.2 contains a server-side req…7.5
- CVE-2026-82272Immich through 3.1.0 fails to properly enforce locked asset …6.5
- CVE-2026-82273Mastra through 1.63.0 contains an authentication bypass vuln…6.5
- CVE-2026-82274Twenty through 2.35.0 contains an open redirect vulnerabilit…4.7
- CVE-2026-82275Qwen-Agent through 0.0.34 contains a path traversal vulnerab…7.5
- CVE-2026-82276StarRocks through 4.0.13 contains an authentication bypass v…5.3
- CVE-2026-82277Argo Rollouts dashboard through 1.10.0 binds to all interfac…9.8
Are you affected by CVE-2026-82271?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
