PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45399 open-webui CVE debrief

Open WebUI versions prior to 0.9.0 contain an authorization flaw (CWE-862) where authenticated users with low privileges can enumerate and terminate background tasks belonging to other users. The vulnerable endpoints—GET /api/tasks and POST /api/tasks/stop/{task_id}—lack proper access controls, enabling any authenticated user to disrupt system-wide chat operations by canceling active tasks across the deployment. This affects multi-user environments where task isolation between users is expected. The vulnerability was published on 2026-05-15 and last modified on 2026-05-19. No known exploitation in ransomware campaigns has been reported.

Vendor
open-webui
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-15
Original CVE updated
2026-05-19
Advisory published
2026-05-15
Advisory updated
2026-05-19

Who should care

Organizations running multi-user Open WebUI deployments prior to 0.9.0, particularly those with untrusted or broadly provisioned user accounts. System administrators responsible for AI platform availability and security teams monitoring for insider threats or lateral movement in self-hosted AI infrastructure.

Technical summary

The vulnerability stems from missing authorization checks on two REST endpoints: GET /api/tasks for listing active background tasks and POST /api/tasks/stop/{task_id} for terminating specific tasks. Authenticated users can access these endpoints regardless of task ownership, violating the principle of least privilege. The attack requires only network access and valid low-privilege credentials, with no user interaction needed. Successful exploitation results in availability impact (task cancellation) and limited information disclosure (task enumeration). The fix in version 0.9.0 implements proper user-scoped authorization for task operations.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade Open WebUI to version 0.9.0 or later to obtain the authorization fix
  • Review and restrict user registration policies to limit untrusted authenticated access
  • Monitor API logs for unusual patterns of task enumeration or termination requests
  • Implement network segmentation to limit exposure of Open WebUI administrative interfaces
  • Validate that background task management endpoints enforce user-scoped authorization after patching

Evidence notes

Authorization bypass confirmed via vendor security advisory. CVSS 3.1 vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H. CPE: cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:* versions before 0.9.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45399 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45399

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45399 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45399

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.