Access Control Flaw in Open WebUI Affecting Model Configuration
CVE-2026-44555

7.6HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-44555?

Open WebUI, a self-hosted artificial intelligence platform, had a significant access control vulnerability prior to version 0.9.0. This flaw allows unauthorized users to exploit the model creation functionality. By referencing restricted base models in their user-defined models, attackers can invoke these models without proper access verification. The vulnerable endpoints permit arbitrary base_model_id values, enabling users with minimal permissions to access and utilize restricted models. This security issue has been addressed in version 0.9.0.

Affected Version(s)

open-webui < 0.9.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.