CVE-2025-63391

7.5

Open-WebUI · Open-WebUI

An authentication bypass vulnerability in Open-WebUI allows unauthorized entities to circumvent security controls.

Executive summary

Open-WebUI contains an authentication bypass vulnerability that permits unauthorized access, posing a high risk to system integrity and data confidentiality.

Vulnerability

The software contains an authentication bypass flaw which may allow an unauthenticated attacker to gain unauthorized access to the application. This vulnerability fundamentally undermines the access control mechanisms designed to protect the user interface.

Business impact

Successful exploitation of this vulnerability allows unauthorized actors to bypass login requirements, potentially granting full access to the application and its underlying data. With a CVSS score of 7.5, this high-severity flaw threatens the confidentiality and integrity of the system, which could lead to significant reputational damage and unauthorized exposure of sensitive information.

Remediation

Immediate Action: Organizations should immediately restrict network access to the Open-WebUI instance and monitor vendor channels for the release of an official security patch.

Proactive Monitoring: Security teams should review application access logs for unusual patterns, such as multiple failed login attempts or successful access from unrecognized IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) to inspect incoming traffic and block suspicious requests that appear to be attempting to bypass authentication endpoints.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score, this vulnerability represents a significant risk to any infrastructure running Open-WebUI. Administrators must prioritize limiting exposure by placing the application behind a secure gateway or VPN and applying official patches as soon as they become available to remediate the underlying authentication flaw.

More Open-WebUI CVEs