PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45350 Openwebui CVE debrief

CVE-2026-45350 is a high-severity authorization flaw in Open WebUI’s chat completion API. Prior to 0.8.6, user-controlled tool selection parameters could be used to reach tools the caller was not permitted to use, creating a tool restriction bypass that may enable unauthorized actions through server-side credentials. The vendor-fixed version is 0.8.6.

Vendor
Openwebui
Product
Open Webui
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-15
Original CVE updated
2026-05-18
Advisory published
2026-05-15
Advisory updated
2026-05-18

Who should care

Administrators and operators of self-hosted Open WebUI deployments, especially those exposing the chat completion API or relying on server tools and tool-server integrations.

Technical summary

According to the NVD record and the GitHub security advisory, the chat_completion API accepts user-supplied tool_ids and tool_servers values that are converted into a tools_dict by middleware and then resolved through get_tool_by_id. The flaw is that no authorization check verifies whether the requesting user is allowed to access the selected tool. As a result, a caller can supply a valid tool ID or tool server reference to invoke a server tool outside their permissions. The advisory also states that the authentication token stored on the server is used when invoking the tool, so the tool execution occurs with server privilege. The affected version range ends before 0.8.6.

Defensive priority

High

Recommended defensive actions

  • Upgrade Open WebUI to version 0.8.6 or later.
  • Review whether the chat completion API is exposed to untrusted users or broader internal audiences.
  • Audit configurations and workflows that rely on server tools or tool_servers/tool_ids inputs.
  • Validate that only intended users can access tool-enabled features after upgrading.
  • Monitor for unexpected tool invocations or permission boundary violations in application logs.

Evidence notes

The supplied NVD record marks the vulnerability as analyzed and lists an official GitHub security advisory as the vendor reference. The advisory and NVD description both identify the issue as an authorization failure in tool selection for the chat completion API, affecting versions before 0.8.6. The CVSS vector is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N, consistent with a network-reachable authorization bypass with confidentiality impact. No KEV entry was supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45350 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45350

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45350 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45350

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.