Improper Access Control in Open WebUI AI Platform by Open WebUI
CVE-2026-45345
6.5MEDIUM
What is CVE-2026-45345?
Open WebUI, a self-hosted AI platform, exhibited a security flaw that allowed users to change another user's model, regardless of its 'Private' visibility setting. This occurred due to insufficient access control measures during the editing process. Users could exploit this vulnerability by altering access permissions, resulting in unauthorized modifications to models. This issue has been addressed in version 0.5.7, which rectifies the permissions handling.
Affected Version(s)
open-webui < 0.5.7
