Information Disclosure in Open WebUI AI Platform by Open WebUI
CVE-2026-45351

6.5MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45351?

Open WebUI is an AI platform designed for offline operation. Prior to version 0.8.9, a security flaw allowed non-admin users to initiate specific API requests. As a result, sensitive system prompts relating to available models set by administrators could be inadvertently exposed to these users, jeopardizing the confidentiality of the application. This vulnerability has been addressed in version 0.8.9.

Affected Version(s)

open-webui < 0.8.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.