SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-82280

HIGH · CVSS 7.1 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Quivr versions up to 0.0.322 are vulnerable due to inadequate ownership validation in prompt endpoints, enabling authenticated users to modify prompts by their identifiers. This flaw allows attackers with read-only access to shared brains to exploit exposed prompt identifiers, potentially overwriting system prompts and impacting all users within the affected environment. Organizations utilizing Quivr should prioritize addressing this vulnerability to prevent unauthorized modifications and protect user data integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82280
Severity
HIGH
CVSS
7.1
EPSS
0.20%

Original NVD Description

Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.