Unauthorized Access to System Prompt in Open WebUI by Open WebUI
CVE-2026-45387
4.3MEDIUM
What is CVE-2026-45387?
The Open WebUI platform, designed for offline AI operations, has a vulnerability that affects model permission settings. Users who are granted read access to certain models can inadvertently gain access to confidential system prompts, which may be considered sensitive information. This issue could lead to unauthorized information disclosure among users. The vulnerability has been addressed in version 0.9.5, where improved access controls now prevent unintended disclosure of system prompts.
Affected Version(s)
open-webui < 0.9.5
