CVE-2026-69098: Unauthenticated Remote Code Execution in kotaemon via Insecure Deserialization
A critical vulnerability (CVE-2026-69098, CVSS 9.8) was discovered in kotaemon through 0.12.0, allowing unauthenticated attackers to achieve remote code execution via insecure deserialization in the check_connection endpoint. Users of kotaemon should update to a version beyond 0.12.0 to mitigate this vulnerability.