Authorization bypass through user-controlled key in Open WebUI - CVE-2026-45666

 

Authorization bypass through user-controlled key in Open WebUI - CVE-2026-45666

Published: May 12, 2026


Vulnerability identifier: #VU131117
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45666
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the /api/v1/notes/{note_id} endpoint when handling requests for note identifiers. A remote user can modify or enumerate note UUIDs to disclose sensitive information.

Exploitation requires the notes feature to be enabled, or for the user to expose the notes interface by modifying the /api/config response in the client.


Affected software

Open WebUI

How to mitigate CVE-2026-45666

Install security update from vendor's website.

Open WebUI - update to 0.8.11

External References

Related Security Bulletins