CVE-2026-45671

8.0

Open WebUI · Open WebUI

Open WebUI is susceptible to an authorization bypass vulnerability allowing authenticated users to manipulate user-controlled keys to access unauthorized data or functions.

Executive summary

An authorization bypass vulnerability in Open WebUI versions prior to 0.9.0 allows authenticated users to escalate their access privileges.

Vulnerability

This vulnerability (CWE-639) exists due to improper authorization checks, where an authenticated user can manipulate parameters to access resources they are not permitted to view or modify.

Business impact

With a CVSS score of 8.0, this vulnerability poses a significant risk to data privacy and platform integrity. An attacker with low-level access could potentially bypass security controls to gain administrative-level visibility or control, resulting in the unauthorized access or modification of sensitive AI session data.

Remediation

Immediate Action: Update Open WebUI to version 0.9.0 or later to resolve the authorization logic flaw.

Proactive Monitoring: Review access logs for abnormal patterns of resource requests or attempts to access administrative endpoints by standard users.

Compensating Controls: Implement strict Role-Based Access Control (RBAC) and review user permissions to minimize the blast radius of compromised accounts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The existence of a proof-of-concept elevates the risk profile of this vulnerability. Organizations should apply the 0.9.0 update immediately to prevent authenticated users from escalating their privileges and compromising the platform's security posture.

More Open WebUI CVEs