CVE ReportsCVE-2026-59215: Insecure Direct Object Reference in Open WebUI Thread Message...
Vulnerability ID: CVE-2026-59215
CVSS Score: 3.1
Published: 2026-07-24
A Broken Object Level Authorization (BOLA) / Insecure Direct Object Reference (IDOR) vulnerability in Open WebUI prior to v0.10.0 allows authenticated users to access and disclose private message contents, thread context, and channel metadata from other restricted private or Direct Message (DM) channels without proper authorization.
Authenticated users can read private messages and channel threads they do not own by exploiting missing channel-binding validation in thread parent-message lookups.
v0.10.0)Fix thread and message channel validation
Remediation Steps:
Read the full report for CVE-2026-59215 on our website for more details including interactive diagrams and full exploit analysis.