Insufficient Authorization in Open WebUI's AI Platform by Open WebUI
CVE-2026-44563
5.4MEDIUM
What is CVE-2026-44563?
Open WebUI, a self-hosted AI platform, had a security flaw in its API where certain endpoints (/api/generate, /api/embed, /api/embeddings, and /api/show) did not properly verify user permissions against model access. This oversight allowed any authenticated user to retrieve data from models they were not authorized to access, potentially exposing sensitive information. Users should upgrade to version 0.9.0 or later to mitigate this issue.
Affected Version(s)
open-webui < 0.9.0
