Vulnerability in Open WebUI AI Platform Allows Unauthorized State Modification
CVE-2026-45316
3.5LOW
What is CVE-2026-45316?
The Open WebUI, a self-hosted AI platform, contains a flaw in the POST /api/v1/notes/{id}/pin endpoint. Prior to version 0.9.3, the system fails to properly enforce write permissions, allowing users with only read access to pin or unpin shared notes. This unauthorized action is a significant concern, as it can alter the intended state of shared resources without appropriate permissions, leading to potential data integrity issues. The vulnerability has been addressed in version 0.9.3.
Affected Version(s)
open-webui < 0.9.3
