Inconsistent Authorization Controls in Open WebUI Affecting User Data Management
CVE-2026-44570
8.3HIGH
What is CVE-2026-44570?
Open WebUI is a self-hosted AI platform that previously lacked proper authorization controls on its memories API. This flaw allowed standard users to access, delete, and restore other users' memory content. Through specific API endpoints, unauthorized users could view existing memories and even delete them, with prompt restoration capabilities. This vulnerability compromised user data integrity and privacy, emphasizing the necessity for strict access controls. The issue was addressed in version 0.6.19.
Affected Version(s)
open-webui < 0.6.19
