CVE-2026-45395

Open WebUI · Open WebUI

A high-severity vulnerability has been identified in the Open WebUI AI platform, requiring immediate attention from security administrators.

Executive summary

A high-severity security vulnerability in Open WebUI poses a risk to platform security, requiring immediate remediation efforts.

Vulnerability

This is a high-severity security flaw in the Open WebUI platform; administrators are encouraged to follow vendor guidance for specific remediation steps.

Business impact

With a CVSS score of 7.2, this vulnerability could potentially lead to unauthorized access or security bypasses within the Open WebUI environment. This presents a risk to the confidentiality and integrity of hosted AI data.

Remediation

Immediate Action: Apply vendor security updates as soon as they become available for the Open WebUI platform.

Proactive Monitoring: Monitor system logs for signs of unauthorized access or exploitation attempts targeting the platform.

Compensating Controls: Restrict access to the platform to authorized internal networks only to minimize the risk of external exploitation.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Security teams must prioritize the update of the Open WebUI platform to the latest version. Given the high-severity rating, maintaining a secure and patched configuration is critical to preventing unauthorized access.