Broken Access Control in Open WebUI Affects AI Platform from Open WebUI
CVE-2026-34222

7.7HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
1 April 2026

What is CVE-2026-34222?

Open WebUI, a self-hosted AI platform, contained a vulnerability that allowed unauthorized access to certain functionalities due to broken access control in tool values. This flaw, present in versions prior to 0.8.11, has serious implications for data security and user privacy. The issue has since been addressed in version 0.8.11, requiring users to update to mitigate potential risks. For further details, please see the security advisory and release notes linked.

Affected Version(s)

open-webui < 0.8.11

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.