What is CVE-2026-69098?
This vulnerability is an insecure deserialization flaw in the 'check_connection' endpoint of kotaemon up to version 0.12.0. Unauthenticated attackers can instantiate arbitrary Python classes via crafted YAML/JSON input with a '__type__' field, potentially leading to remote code execution. Immediate update to the latest version is recommended.
Azərbaycanca: Bu boşluq kotaemon proqramının 0.12.0 versiyasına qədər olan versiyalarında 'check_connection' funksiyasında təhlükəli deserializasiya zəifliyidir. Doğrulama olmadan xüsusi hazırlanmış YAML/JSON girişləri ilə təsdiqlənməmiş hücumçular ixtiyari Python sinifləri yaradaraq sistemdə kod icrası əldə edə bilər. Dərhal proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Is authentication required to exploit CVE-2026-69098?
No, this vulnerability can be exploited by unauthenticated attackers.
In which function of kotaemon does CVE-2026-69098 exist?
The vulnerability exists in the `check_connection` endpoint of kotaemon.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.