Unauthorized Access in Open WebUI AI Platform by Open WebUI
CVE-2026-45397
5.3MEDIUM
What is CVE-2026-45397?
The Open WebUI platform, designed for offline AI operations, exposes sensitive RAG pipeline configurations to any unauthenticated HTTP client prior to version 0.9.5. Unlike other secured endpoints such as /embedding and /config, this particular endpoint lacks necessary access restrictions, posing a risk of data exposure. This oversight could allow for unauthorized users to retrieve critical operational details. The issue is addressed in version 0.9.5, which introduces the required authentication mechanisms to safeguard against such vulnerabilities.
Affected Version(s)
open-webui < 0.9.5
