Unauthorized Access in Open WebUI AI Platform by Open WebUI
CVE-2026-45397

5.3MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45397?

The Open WebUI platform, designed for offline AI operations, exposes sensitive RAG pipeline configurations to any unauthenticated HTTP client prior to version 0.9.5. Unlike other secured endpoints such as /embedding and /config, this particular endpoint lacks necessary access restrictions, posing a risk of data exposure. This oversight could allow for unauthorized users to retrieve critical operational details. The issue is addressed in version 0.9.5, which introduces the required authentication mechanisms to safeguard against such vulnerabilities.

Affected Version(s)

open-webui < 0.9.5

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.