CVE-2026-55880
openreplay
OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the ownership predicate that their sibling read and edit functions use: notes.delete filtered only on note id and project id, while dashboards.update_widget and dashboards.remove_widget filtered only on dashboard id and widget id, allowing any authenticated member to delete another user's private session notes and remove or rewrite widgets on another user's private dashboards.
- CVSS
- 7.1
- EPSS
- 0.19% 9.49% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11