User Role Validation Flaw in Open WebUI AI Platform
CVE-2026-44567
7.3HIGH
What is CVE-2026-44567?
The Open WebUI platform, an offline AI solution, has a vulnerability in its API related to user role validation. In versions before 0.1.124, the application fails to ensure that users possess the correct authorization level upon registration. With new sign-ups enabled, newly registered users automatically receive a 'pending' role. This configuration necessitates admin intervention to alter the user's role to 'user' or 'admin', allowing access to the web application. If an administrator neglects to perform this step, unauthorized individuals may gain access, posing a security risk.
Affected Version(s)
open-webui < 0.1.124
