CVE-2026-45301: Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
(updated )
A missing permission check in all files related API endpoints allows any authenticated user to list, access and delete every file uploaded by every user to the platform.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-45301 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →