Access Control Flaw in Open WebUI AI Platform by Open WebUI
CVE-2026-54019

6.5MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
23 June 2026

What is CVE-2026-54019?

Open WebUI, a self-hosted AI platform, faced a security challenge prior to version 0.9.6, where an incomplete fix for an earlier vulnerability allowed bypassing collection-level access control lists (ACL) in the Milvus multitenancy mode. This oversight permitted users to leverage unauthorized non-KB collection names as ephemeral collections, which were then processed without proper escaping, leading to exposure of sensitive resources.

Affected Version(s)

open-webui < 0.9.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.