PatchSiren

open-webui CVE debriefs · Page 4

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH open-webui CVE published 2026-05-15

CVE-2026-45399

Open WebUI versions prior to 0.9.0 contain an authorization flaw (CWE-862) where authenticated users with low privileges can enumerate and terminate background tasks belonging to other users. The vulnerable endpoints—GET /api/tasks and POST /api/tasks/stop/{task_id}—lack proper access controls, enabling any authenticated user to disrupt system-wide chat operations by canceling active tasks across the depl [truncated]

HIGH open-webui CVE published 2026-05-15

CVE-2026-45349

Open WebUI versions prior to 0.9.0 contain an authorization bypass vulnerability in the chat completions API. An authenticated user can access and continue another user's conversation by supplying their own valid API key alongside the target user's Chat ID to the /api/chat/completions endpoint. The vulnerability stems from improper authorization checks that fail to verify the requesting user's ownership o [truncated]

MEDIUM open-webui CVE published 2026-05-15

CVE-2026-45339

Open WebUI versions prior to 0.9.0 contain an authorization bypass vulnerability in API key endpoint restrictions. When administrators configure API keys with restricted endpoint access, the restriction is properly enforced for requests using the `Authorization: Bearer sk-...` header format, returning HTTP 403 Forbidden. However, identical API keys submitted via the `x-api-key` header bypass these restric [truncated]

MEDIUM open-webui CVE published 2026-05-15

CVE-2026-44568

A stored cross-site scripting (XSS) vulnerability exists in Open WebUI prior to version 0.9.0. The AccountPending.svelte component renders administrator-configured

MEDIUM open-webui CVE published 2026-05-15

CVE-2026-44564

Open WebUI versions prior to 0.9.0 contain an authorization bypass vulnerability in the Socket.IO real-time collaboration subsystem. The ydoc:document:update event handler validates that a user is a member of a document's Socket.IO room but fails to verify write permissions. Users with read-only access can join document rooms via ydoc:document:join (which only requires read permission) and subsequently em [truncated]

MEDIUM open-webui CVE published 2026-05-15

CVE-2026-44563

Open WebUI versions prior to 0.9.0 contain a broken access control vulnerability (CWE-862) affecting four API endpoints: /api/generate, /api/embed, /api/embeddings, and /api/show. These endpoints accept arbitrary model names from authenticated users and forward requests to the Ollama backend without verifying whether the requesting user has explicit authorization to access the specified model. The endpoin [truncated]

MEDIUM open-webui CVE published 2026-05-15

CVE-2026-44562

Open WebUI versions prior to 0.9.0 contain an insecure direct object reference vulnerability in the model import functionality. The POST /api/v1/models/import endpoint allows authenticated users with workspace.models_import permission to overwrite any existing model in the database by specifying a matching model ID in their import payload. The endpoint merges attacker-controlled data over existing model r [truncated]

MEDIUM open-webui CVE published 2026-05-15

CVE-2026-44561

Open WebUI versions prior to 0.9.0 contain an authorization bypass vulnerability in channel membership validation. The `is_user_channel_member` function checks for the existence of a `ChannelMember` record but fails to verify the `is_active` field. When users are deactivated from a group or direct message channel—whether removed by the channel owner or through voluntary departure—their membership row pers [truncated]

MEDIUM open-webui CVE published 2026-05-15

CVE-2026-44560

Open WebUI versions prior to 0.9.0 contain an authorization bypass vulnerability in the `get_sources_from_items` function. The vulnerability affects three specific code paths: `type:

MEDIUM open-webui CVE published 2026-05-15

CVE-2026-44559

A missing authorization check in Open WebUI's channel member enumeration endpoint allows authenticated users to list members of private channels without access. The GET /api/v1/channels/{id}/members endpoint only validates membership for group and direct message channels, leaving standard channels—including private ones—unprotected. Any authenticated user with knowledge of a private channel's UUID can ret [truncated]

MEDIUM open-webui CVE published 2026-05-15

CVE-2026-44558

A missing authorization check in Open WebUI's channel router allows non-admin users to bypass access controls. Prior to version 0.9.0, the create and update paths for group channels fail to invoke `filter_allowed_access_grants`, permitting users with channel creation or ownership privileges to submit arbitrary access grants—including public wildcard grants—without administrative validation. This enables u [truncated]

MEDIUM open-webui CVE published 2026-05-15

CVE-2026-44557

Open WebUI versions prior to 0.9.0 contain an authorization bypass vulnerability in the `_validate_collection_access` function. The function uses an incomplete allowlist that only enforces ownership checks for collections matching `user-memory-*` and `file-*` patterns. All other collection names pass through unchecked, including the system-level `knowledge-bases` meta-collection that stores IDs, names, an [truncated]

HIGH open-webui CVE published 2026-05-15

CVE-2026-44555

CVE-2026-44555 is a high-severity access control flaw in Open WebUI’s model composition feature. Before 0.9.0, a user could create or import a composed model that pointed to a restricted base model, then invoke it even though they were not authorized for the underlying base model. The server would forward the request to that restricted model using the admin-configured API key, creating unauthorized access [truncated]

HIGH open-webui CVE published 2026-05-15

CVE-2026-44554

Open WebUI versions prior to 0.9.0 contain a broken access control vulnerability in the document retrieval API. The POST /api/v1/retrieval/process/web endpoint accepts user-supplied collection_name and overwrite parameters without verifying ownership or write permissions. When overwrite=True (the default), the application deletes the target collection via VECTOR_DB_CLIENT.delete_collection() before writin [truncated]

HIGH open-webui CVE published 2026-05-15

CVE-2026-44553

Open WebUI versions prior to 0.9.0 fail to invalidate active Socket.IO sessions when administrative privileges are revoked or user accounts are deleted. The SESSION_POOL cache is not updated to reflect role changes, allowing a former administrator to retain elevated access within their existing session as long as the connection remains active through automatic heartbeats. This represents a session managem [truncated]

HIGH open-webui CVE published 2026-05-15

CVE-2026-44552

CVE-2026-44552 affects Open WebUI deployments that share a Redis database across multiple instances. Prior to version 0.9.0, the tool_servers and terminal_servers keys in utils/tools.py were not prefixed, so values could collide between instances. In supported multi-instance setups, an administrator on one instance could overwrite the configuration read by another instance, causing users on the second ins [truncated]

CRITICAL open-webui CVE published 2026-05-15

CVE-2026-44551

CVE-2026-44551 is a critical authentication flaw in Open WebUI prior to 0.9.0. The LDAP login path did not require a non-empty password before attempting a Simple Bind, and on vulnerable LDAP servers that bind could succeed and result in a full session token being issued for the target user.