Improper Access Control in Open WebUI AI Platform by Open WebUI
CVE-2026-45345

6.5MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45345?

Open WebUI, a self-hosted AI platform, exhibited a security flaw that allowed users to change another user's model, regardless of its 'Private' visibility setting. This occurred due to insufficient access control measures during the editing process. Users could exploit this vulnerability by altering access permissions, resulting in unauthorized modifications to models. This issue has been addressed in version 0.5.7, which rectifies the permissions handling.

Affected Version(s)

open-webui < 0.5.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.