Authorization Flaw in Open WebUI AI Platform
CVE-2026-45399
7.1HIGH
What is CVE-2026-45399?
The Open WebUI platform, designed for offline AI operations, faced a serious authorization vulnerability where low-privileged authenticated users could manipulate system tasks. Specifically, they could enumerate active background tasks and terminate tasks belonging to other users, disrupting multi-user workflows and diminishing system integrity. This flaw was addressed in version 0.9.0 to enhance user permissions and protect task management features.
Affected Version(s)
open-webui < 0.9.0
