Session Management Flaw in Open WebUI Affects Administrative Controls
CVE-2026-44553
8.1HIGH
What is CVE-2026-44553?
The Open WebUI platform, designed for offline operation, has a session management flaw affecting role changes and user deletions. Specifically, prior to version 0.9.0, when an administrator's role is revoked or a user is deleted, existing sessions remain active due to failure to clear the SESSION_POOL. This oversight allows users to retain admin privileges in their Socket.IO sessions as long as they maintain their connection. The vulnerability is acknowledged and addressed in version 0.9.0, enhancing the security of role management and session integrity.
Affected Version(s)
open-webui < 0.9.0
