Authorization Bypass in Open WebUI Artificial Intelligence Platform
CVE-2026-54012

7.1HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
23 June 2026

What is CVE-2026-54012?

Open WebUI, a self-hosted artificial intelligence platform, allows users to create and manipulate workspace models. In versions prior to 0.9.6, the platform permits users to store arbitrary 'meta.knowledge' entries without proper verification of ownership or access rights. This oversight can be exploited by a malicious model owner, enabling them to link another user's file ID to their metadata. As a result, the attacker can access and potentially delete private files belonging to other users. The vulnerability has been addressed in version 0.9.6.

Affected Version(s)

open-webui < 0.9.6

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.