← Terug naar overzicht

CVE-2026-82283 affects VoltAgent through version 2.1.20, where memory API handlers fail to validate conversation ownership. This allows authenticated users to access, modify, and delete other users' conversations and messages by supplying caller-controlled identifiers to memory endpoints. The vulnerability is classified as a broken object-level authorization (BOLA/IDOR) issue. An attacker only needs to be authenticated to exploit this flaw, lowering the bar for abuse. The affected code resides in the server-core package's memory handlers. Fixes and advisories have been published via GitHub and VulnCheck. Users are advised to update beyond version 2.1.20 as soon as a patch is available.

Affected products

  • VoltAgent 2.1.20 and earlier

Related CVE's

  • CVE-2026-82283

Categories

  • Enterprise Applications
  • Identity & Access
  • Web Technologies