PT-2026-41199 · Unknown · Open-Webui

Published

2026-03-18

·

Updated

2026-05-16

·

CVE-2026-45666

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI versions prior to 0.8.11
Description The API endpoint '/api/v1/notes/{note id}' lacks proper authorization checks, allowing authenticated users to retrieve notes belonging to other users by guessing or enumerating note id UUIDs. This can lead to the unauthorized disclosure of sensitive or private user data. If the notes feature is disabled in the UI, an attacker can potentially enable it via the '/api/config' endpoint to facilitate the attack.
Recommendations Update to version 0.8.11 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07457
CVE-2026-45666
GHSA-X3QM-P8HR-3C3H

Affected Products

Open-Webui