CVE-2026-34222
7.7Open WebUI · Open WebUI
Open WebUI prior to version 0.8.11 contains a broken access control vulnerability in tool values that allows unauthorized access.
Executive summary
A broken access control vulnerability in Open WebUI versions prior to 0.8.11 poses a significant risk of unauthorized data exposure.
Vulnerability
This vulnerability involves an improper authorization flaw (CWE-285) within the tool values functionality. The vulnerability requires the attacker to have low-level privileges (authenticated user) to exploit the access control weakness.
Business impact
The flaw allows an authenticated user to access information that should be restricted, potentially leading to unauthorized data disclosure. Given the CVSS score of 7.7, this is classified as a High-severity issue that could compromise the confidentiality of sensitive AI-driven workflows and proprietary data.
Remediation
Immediate Action: Update the Open WebUI installation to version 0.8.11 or later to resolve the underlying authorization defect.
Proactive Monitoring: Review application access logs for unusual patterns or attempts by standard users to access administrative or restricted tool configuration endpoints.
Compensating Controls: Implement strict network-level access controls to limit exposure of the Open WebUI interface to trusted internal networks only, reducing the attack surface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing Open WebUI must prioritize upgrading to version 0.8.11 immediately. Because this vulnerability involves broken access controls, standard authentication measures are insufficient to stop an attacker who has already gained low-level access to the platform. Applying the vendor-supplied patch is the only definitive way to secure the system against this risk.