Unauthorized Access to System Prompt in Open WebUI by Open WebUI
CVE-2026-45387

4.3MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45387?

The Open WebUI platform, designed for offline AI operations, has a vulnerability that affects model permission settings. Users who are granted read access to certain models can inadvertently gain access to confidential system prompts, which may be considered sensitive information. This issue could lead to unauthorized information disclosure among users. The vulnerability has been addressed in version 0.9.5, where improved access controls now prevent unintended disclosure of system prompts.

Affected Version(s)

open-webui < 0.9.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.