Authorization Bypass in Open WebUI by Artificial Intelligence Platform Vendor
CVE-2026-45339
6.5MEDIUM
What is CVE-2026-45339?
Open WebUI, an offline self-hosted AI platform, has a vulnerability that allows an API key to bypass endpoint restrictions. Although admin restrictions properly block requests using the 'Authorization: Bearer sk-...' header with a 403 error, the same key sent through the 'x-api-key' header is not restricted, enabling unauthorized access to API functionalities. This issue was addressed in version 0.9.0.
Affected Version(s)
open-webui < 0.9.0
