Sploitus

CVE-2026-69098

2 known exploits for CVE-2026-69098

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges.

Affected products
Kotaemon
CVSS 3.1
9.8 CRITICAL
EPSS
0.5% (41th percentile)
Weakness
CWE-502
NVD status
Received
Published
2026-08-04
CVE-2026-69098 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-69098

Proof-of-concept code and exploit modules indexed by Sploitus