PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45316 open-webui CVE debrief

## Summary CVE-2026-45316 is a low-severity authorization bypass in Open WebUI, a self-hosted AI platform. The vulnerability allows users with read-only access to shared notes to perform state-modifying actions (pinning/unpinning) due to improper permission checks on the POST /api/v1/notes/{id}/pin endpoint. The endpoint verifies read permission instead of write permission before executing the toggle operation on the is_pinned field. ## Technical Details - **Affected Product:** Open WebUI (self-hosted AI platform) - **Affected Versions:** Prior to 0.9.3 - **Vulnerable Endpoint:** POST /api/v1/notes/{id}/pin - **Root Cause:** CWE-863 (Incorrect Authorization) — the endpoint performs a write operation but only validates read permission - **Attack Vector:** Network-based, requires low-privilege authenticated access - **Impact:** Low integrity impact; unauthorized modification of note pinning state The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N) reflects that exploitation requires network access, low privileges, and user interaction, with no confidentiality or availability impact and low integrity impact. ## Timeline - **CVE Published:** 2026-05-15 - **CVE Last Modified:** 2026-05-18 - **Fix Available:** Version 0.9.3 ## Recommended Actions 1. **Upgrade Immediately:** Update Open WebUI to version 0.9.3 or later, which contains the fix for this authorization bypass. 2. **Access Control Review:** Audit shared note permissions to ensure read-only users have not made unauthorized pinning changes. 3. **Monitor for Anomalies:** Review note pinning activity logs for unexpected state changes by read-only users during the exposure window. 4. **Validate Permission Model:** After upgrading, verify that the pin/unpin functionality correctly requires write permission through functional testing. ## References See resourceLinkAnnotations for official CVE record, NVD details, and vendor security advisory.

Vendor
open-webui
Product
Unknown
CVSS
LOW 3.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-15
Original CVE updated
2026-05-18
Advisory published
2026-05-15
Advisory updated
2026-05-18

Who should care

Open WebUI administrators managing multi-user deployments with shared notes and role-based access controls.

Technical summary

The POST /api/v1/notes/{id}/pin endpoint in Open WebUI prior to 0.9.3 incorrectly validates read permission instead of write permission when toggling the is_pinned field. This allows read-only users to modify note state. Fixed in version 0.9.3.

Defensive priority

low

Recommended defensive actions

  • Upgrade Open WebUI to version 0.9.3 or later
  • Audit shared note permissions for unauthorized pinning changes
  • Review note pinning activity logs for anomalies
  • Validate pin/unpin functionality requires write permission after upgrade

Evidence notes

CVE description and CVSS vector sourced from NVD record. Vendor advisory confirms fix in version 0.9.3. CWE-863 classification from GitHub Security Advisory.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45316 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45316

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45316 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45316

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.