CVE-2026-45675
8.1Open WebUI · Open WebUI
Open WebUI is vulnerable to improper privilege management and race condition flaws, which may allow an unauthenticated attacker to achieve full system compromise.
Executive summary
A critical vulnerability in Open WebUI versions prior to 0.9.0 permits unauthorized privilege escalation and exploitation through race conditions.
Vulnerability
The application suffers from CWE-269 (Improper Privilege Management) and CWE-362 (Race Condition), allowing an unauthenticated attacker to manipulate system resources and escalate privileges.
Business impact
The CVSS score of 8.1 reflects a high risk of total system compromise, including unauthorized data access and potential service disruption. Successful exploitation could lead to the total loss of confidentiality, integrity, and availability of the self-hosted AI platform and its underlying host environment.
Remediation
Immediate Action: Upgrade the Open WebUI package to version 0.9.0 or later immediately.
Proactive Monitoring: Monitor system logs for unusual process concurrency or unexpected privilege changes that may indicate exploitation attempts.
Compensating Controls: Ensure the instance is restricted to trusted internal networks and utilize a WAF to filter potentially malicious traffic.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the severity of potential privilege escalation, administrators must prioritize updating to version 0.9.0. Failure to patch leaves the platform vulnerable to unauthenticated attackers seeking to gain full control of the application environment.