Access Control Flaw in Open WebUI Affecting Model Configuration
CVE-2026-44555
7.6HIGH
What is CVE-2026-44555?
Open WebUI, a self-hosted artificial intelligence platform, had a significant access control vulnerability prior to version 0.9.0. This flaw allows unauthorized users to exploit the model creation functionality. By referencing restricted base models in their user-defined models, attackers can invoke these models without proper access verification. The vulnerable endpoints permit arbitrary base_model_id values, enabling users with minimal permissions to access and utilize restricted models. This security issue has been addressed in version 0.9.0.
Affected Version(s)
open-webui < 0.9.0
