CVE-2026-42276: Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_session_id} endpoint lets any authenticated user stop any other user's active c...

Added to the CISA Known Exploited Vulnerabilities catalog on 08 May 2026. Vendor: AI/ML. Product: LLM. CVSS score: 4.3.

Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_session_id} endpoint lets any authenticated user stop any other user's active chat session. The endpoint checks authentication but never verifies the session belongs to the caller...

Required action: Review and patch if applicable to your AI infrastructure.