PatchSiren cyber security CVE debrief
CVE-2026-82280 QuivrHQ CVE debrief
CVE-2026-82280 is a high-severity vulnerability in Quivr, a tool that allows users to create and manage prompts. The vulnerability, which has a CVSS score of 7.1, occurs because Quivr fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. This could potentially allow attackers with read-only access to shared brains to read exposed prompt identifiers and overwrite system prompts, affecting all brain users.
- Vendor
- QuivrHQ
- Product
- quivr
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-28
- Original CVE updated
- 2026-09-23
- Advisory published
- 2026-08-28
- Advisory updated
- 2026-09-23
Who should care
Defenders who manage Quivr systems should assess exposure and verify the vulnerability, as it could allow attackers to modify system prompts and potentially affect all brain users.
Why it matters
CVE-2026-82280 is a high-severity vulnerability in Quivr that allows authenticated users to modify any prompt by identifier, potentially affecting all brain users. Defenders should prioritize verifying the vulnerability and assessing exposure.
- Authenticated users can modify any prompt by identifier
- Attackers with read-only access to shared brains can read exposed prompt identifiers
- System prompts can be overwritten, affecting all brain users
Technical summary
The vulnerability occurs because Quivr fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. This could potentially allow attackers with read-only access to shared brains to read exposed prompt identifiers and overwrite system prompts, affecting all brain users. The vulnerability affects Quivr version 0.0.322 and has a CVSS score of 7.1, indicating a high-severity vulnerability. Defenders should prioritize verifying the vulnerability and assessing exposure, as the vulnerability could allow attackers to modify system prompts and potentially affect all brain users.
Defensive priority
Defenders should prioritize verifying the vulnerability and assessing exposure, as the vulnerability could allow attackers to modify system prompts and potentially affect all brain users.
Recommended defensive actions
- Verify the vulnerability and assess exposure
- Check if the system is using Quivr version 0.0.322
- Consider implementing additional security measures to prevent attackers from modifying system prompts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is caused by a lack of ownership validation in prompt endpoints, allowing authenticated users to modify any prompt by identifier. The vulnerability affects Quivr version 0.0.322. This issue may allow attackers with read-only access to shared brains to read exposed prompt identifiers and overwrite system prompts, affecting all brain users. Defenders should verify the vulnerability and assess exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82280 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82280
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82280 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82280
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/QuivrHQ/quivr
-
Source reference
Unverified legacy reference
URL: https://github.com/QuivrHQ/quivr/blob/v0.0.322/backend/api/quivr_api/modules/prompt/controller/prompt_routes.py
-
Source reference
Unverified legacy reference
URL: https://github.com/QuivrHQ/quivr/issues/3698
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/quivr-prompt-endpoints-missing-ownership-validation
-
Source reference
Unverified legacy reference
URL: https://github.com/The-Vibe-Company/Quivr/issues/3698
134c704f-9b21-4f2e-91b3-4a467353bcc0
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.