CVE-2026-82271: R2R Missing Ownership Check Allows Modifying Other Users' Conversations
R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename conversations and append messages to other users' conversation histories, corrupting state and injecting malicious content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
R2Rto a version that resolves this vulnerability.Fixed in 3.6.5
Event History
Frequently Asked Questions
What level of access does an attacker need?
The attacker needs an authenticated R2R account. The attack is network-accessible and requires no user interaction.
Which R2R versions are affected?
R2R through version 3.6.5 is affected. The provided information does not identify a fixed version.
Does this issue expose conversation contents or disrupt service availability?
The supplied CVSS vector indicates no confidentiality or availability impact. Its primary impact is integrity: an attacker can alter conversation names and add content to another user's conversation history.