Key Collision Vulnerability in Open WebUI Artificial Intelligence Platform
CVE-2026-44552

8.7HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-44552?

The Open WebUI artificial intelligence platform, designed for offline use, has a vulnerability concerning key collisions when multiple instances share a Redis database. Prior to version 0.9.0, the application lacks a key prefix in its tool_servers and terminal_servers configurations, which leads to overwritten values when instances A and B write to the same Redis database. This can misconfigure the tool server settings for users on Instance B, inadvertently exposing them to Instance A's configurations. This issue has been addressed in version 0.9.0.

Affected Version(s)

open-webui < 0.9.0

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.