Authorization Bypass in Open WebUI by Artificial Intelligence Platform Vendor
CVE-2026-45339

6.5MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45339?

Open WebUI, an offline self-hosted AI platform, has a vulnerability that allows an API key to bypass endpoint restrictions. Although admin restrictions properly block requests using the 'Authorization: Bearer sk-...' header with a 403 error, the same key sent through the 'x-api-key' header is not restricted, enabling unauthorized access to API functionalities. This issue was addressed in version 0.9.0.

Affected Version(s)

open-webui < 0.9.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.