IDOR vulnerability in Open WebUI Channels feature allows unauthorized message modification
CVE-2026-45385
4.3MEDIUM
What is CVE-2026-45385?
Open WebUI, a self-hosted artificial intelligence platform, contains a vulnerability in its Channels feature that allows any member of a channel to manipulate messages sent by other members. This issue arises in the update_message_by_id function, where check mechanisms only verify if a user is part of the channel, without confirming ownership of messages. As a result, any participant can alter messages, potentially leading to misinformation and security risks. This vulnerability has been addressed in version 0.9.5.
Affected Version(s)
open-webui < 0.9.5
