PT-2026-41199 · Unknown · Open-Webui
Published
2026-03-18
·
Updated
2026-05-16
·
CVE-2026-45666
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open WebUI versions prior to 0.8.11
Description
The API endpoint '/api/v1/notes/{note id}' lacks proper authorization checks, allowing authenticated users to retrieve notes belonging to other users by guessing or enumerating
note id UUIDs. This can lead to the unauthorized disclosure of sensitive or private user data. If the notes feature is disabled in the UI, an attacker can potentially enable it via the '/api/config' endpoint to facilitate the attack.Recommendations
Update to version 0.8.11 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open-Webui