Authorization Bypass in Open WebUI AI Platform
CVE-2026-44560

6.5MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-44560?

Open WebUI, a self-hosted artificial intelligence platform, has a vulnerability in versions prior to 0.9.0 that allows unauthorized users to perform vector store queries in the get_sources_from_items function. This flaw arises from insufficient authorization checks for certain file and collection path types, enabling access to protected content. Users can exploit this oversight to retrieve sensitive information from files and knowledge bases without appropriate permissions.

Affected Version(s)

open-webui < 0.9.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.