CVE-2026-29071: Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories
Any authenticated user can read other users’ private memories via /api/v1/retrieval/query/collection
References
Code Behaviors & Features
Detect and mitigate CVE-2026-29071 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →