User Role Validation Flaw in Open WebUI AI Platform
CVE-2026-44567

7.3HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-44567?

The Open WebUI platform, an offline AI solution, has a vulnerability in its API related to user role validation. In versions before 0.1.124, the application fails to ensure that users possess the correct authorization level upon registration. With new sign-ups enabled, newly registered users automatically receive a 'pending' role. This configuration necessitates admin intervention to alter the user's role to 'user' or 'admin', allowing access to the web application. If an administrator neglects to perform this step, unauthorized individuals may gain access, posing a security risk.

Affected Version(s)

open-webui < 0.1.124

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.