PatchSiren cyber security CVE debrief
CVE-2026-45385 open-webui CVE debrief
An Insecure Direct Object Reference (IDOR) vulnerability in Open WebUI's Channels feature allows any authenticated channel member to modify messages sent by other members, including administrators. The flaw exists in the `update_message_by_id` function, which only verifies channel membership via `is_user_channel_member` without checking message ownership. This affects group and direct message channels in versions prior to 0.9.5. The vulnerability was published on 2026-05-15 and last modified on 2026-05-19.
- Vendor
- open-webui
- Product
- Unknown
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-15
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-15
- Advisory updated
- 2026-05-19
Who should care
Organizations running self-hosted Open WebUI instances with the Channels feature enabled, particularly those using group channels for collaborative AI interactions or relying on message integrity for compliance or operational purposes.
Technical summary
The vulnerability stems from missing ownership verification in the message update workflow. When processing `update_message_by_id` requests for group or DM channels, the application validates that the requesting user is a channel member but fails to verify that the user owns the specific message being modified. This allows any authenticated member to craft API requests targeting arbitrary message IDs within shared channels, resulting in unauthorized message modification. The fix in version 0.9.5 adds proper message ownership validation to the authorization flow.
Defensive priority
medium
Recommended defensive actions
- Upgrade Open WebUI to version 0.9.5 or later to remediate this vulnerability
- Review channel message audit logs for unauthorized modifications if running affected versions
- Implement additional authorization checks in custom deployments if immediate patching is not feasible
- Monitor for anomalous message edit patterns in channel activity logs
Evidence notes
The vulnerability is documented in a GitHub Security Advisory (GHSA-wwhq-cx22-f7vv) with tags indicating exploit availability, mitigation guidance, and vendor advisory status. The NVD record confirms the affected CPE as `cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*` with version end excluding 0.9.5. CVSS 3.1 vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N. CWE-639 (Authorization Bypass Through User-Controlled Key) is identified as the weakness type.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45385 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45385
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45385 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45385
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/open-webui/open-webui/security/advisories/GHSA-wwhq-cx22-f7vv
[email protected] - Exploit, Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.