IDOR vulnerability in Open WebUI Channels feature allows unauthorized message modification
CVE-2026-45385

4.3MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45385?

Open WebUI, a self-hosted artificial intelligence platform, contains a vulnerability in its Channels feature that allows any member of a channel to manipulate messages sent by other members. This issue arises in the update_message_by_id function, where check mechanisms only verify if a user is part of the channel, without confirming ownership of messages. As a result, any participant can alter messages, potentially leading to misinformation and security risks. This vulnerability has been addressed in version 0.9.5.

Affected Version(s)

open-webui < 0.9.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.