PatchSiren cyber security CVE debrief
CVE-2026-45316 open-webui CVE debrief
## Summary CVE-2026-45316 is a low-severity authorization bypass in Open WebUI, a self-hosted AI platform. The vulnerability allows users with read-only access to shared notes to perform state-modifying actions (pinning/unpinning) due to improper permission checks on the POST /api/v1/notes/{id}/pin endpoint. The endpoint verifies read permission instead of write permission before executing the toggle operation on the is_pinned field. ## Technical Details - **Affected Product:** Open WebUI (self-hosted AI platform) - **Affected Versions:** Prior to 0.9.3 - **Vulnerable Endpoint:** POST /api/v1/notes/{id}/pin - **Root Cause:** CWE-863 (Incorrect Authorization) — the endpoint performs a write operation but only validates read permission - **Attack Vector:** Network-based, requires low-privilege authenticated access - **Impact:** Low integrity impact; unauthorized modification of note pinning state The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N) reflects that exploitation requires network access, low privileges, and user interaction, with no confidentiality or availability impact and low integrity impact. ## Timeline - **CVE Published:** 2026-05-15 - **CVE Last Modified:** 2026-05-18 - **Fix Available:** Version 0.9.3 ## Recommended Actions 1. **Upgrade Immediately:** Update Open WebUI to version 0.9.3 or later, which contains the fix for this authorization bypass. 2. **Access Control Review:** Audit shared note permissions to ensure read-only users have not made unauthorized pinning changes. 3. **Monitor for Anomalies:** Review note pinning activity logs for unexpected state changes by read-only users during the exposure window. 4. **Validate Permission Model:** After upgrading, verify that the pin/unpin functionality correctly requires write permission through functional testing. ## References See resourceLinkAnnotations for official CVE record, NVD details, and vendor security advisory.
- Vendor
- open-webui
- Product
- Unknown
- CVSS
- LOW 3.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-15
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-15
- Advisory updated
- 2026-05-18
Who should care
Open WebUI administrators managing multi-user deployments with shared notes and role-based access controls.
Technical summary
The POST /api/v1/notes/{id}/pin endpoint in Open WebUI prior to 0.9.3 incorrectly validates read permission instead of write permission when toggling the is_pinned field. This allows read-only users to modify note state. Fixed in version 0.9.3.
Defensive priority
low
Recommended defensive actions
- Upgrade Open WebUI to version 0.9.3 or later
- Audit shared note permissions for unauthorized pinning changes
- Review note pinning activity logs for anomalies
- Validate pin/unpin functionality requires write permission after upgrade
Evidence notes
CVE description and CVSS vector sourced from NVD record. Vendor advisory confirms fix in version 0.9.3. CWE-863 classification from GitHub Security Advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45316 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45316
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45316 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45316
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/open-webui/open-webui/security/advisories/GHSA-jx2x-j75f-xq3j
[email protected] - Exploit, Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.