CVE-2026-45666: Open WebUI has an Indirect Object Reference (IDOR) in user notes
(updated )
The API /api/v1/notes/{note_id} endpoint lacks proper authorization checks, allowing authenticated users to retrieve notes belonging to other users by guessing or enumerating UUIDs. This results in unauthorized disclosure of potentially sensitive or private user data.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-45666 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →