CVE-2026-82271
Received Received - Intake

Authenticated Conversation Manipulation in R2R

Vulnerability report for CVE-2026-82271, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: VulnCheck

Description

R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename conversations and append messages to other users' conversation histories, corrupting state and injecting malicious content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sciphi-ai r2r to 3.6.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-82271 is an Insecure Direct Object Reference (IDOR) vulnerability in R2R versions 3.6.5 and earlier. It allows authenticated users to modify conversations belonging to other users by supplying arbitrary conversation identifiers. Attackers can rename conversations or append messages to other users' conversation histories, corrupting data integrity and enabling malicious content injection.

Impact Analysis

If you use R2R, attackers with valid credentials could alter your conversations, inject harmful content, or corrupt conversation states. This could lead to misinformation, data leaks, or unauthorized access to sensitive information stored in conversations.

Compliance Impact

This vulnerability could violate GDPR's integrity and confidentiality requirements by allowing unauthorized data modification. For HIPAA, it risks exposing protected health information through conversation tampering. Organizations may face compliance failures, legal penalties, and reputational damage.

Mitigation Strategies

Upgrade R2R to a version later than 3.6.5 to address the missing ownership validation in conversation handlers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82271. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart