Access Control Weakness in Open WebUI Platform
CVE-2026-45365
5.4MEDIUM
What is CVE-2026-45365?
The Open WebUI platform, an offline AI application, exposes a security flaw that allows authenticated users to bypass model access control measures. Specifically, a parameter named 'bypass_filter' can be appended to certain HTTP endpoints, enabling the invocation of admin-restricted models. This bypass capability is a significant risk, potentially allowing unauthorized access to sensitive functionalities. The issue has been addressed in version 0.8.11.
Affected Version(s)
open-webui < 0.8.11
