Insufficient Authorization in Open WebUI's AI Platform by Open WebUI
CVE-2026-44563

5.4MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-44563?

Open WebUI, a self-hosted AI platform, had a security flaw in its API where certain endpoints (/api/generate, /api/embed, /api/embeddings, and /api/show) did not properly verify user permissions against model access. This oversight allowed any authenticated user to retrieve data from models they were not authorized to access, potentially exposing sensitive information. Users should upgrade to version 0.9.0 or later to mitigate this issue.

Affected Version(s)

open-webui < 0.9.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.