Access Control Flaw in Open WebUI AI Platform by Open WebUI
CVE-2026-54019
6.5MEDIUM
What is CVE-2026-54019?
Open WebUI, a self-hosted AI platform, faced a security challenge prior to version 0.9.6, where an incomplete fix for an earlier vulnerability allowed bypassing collection-level access control lists (ACL) in the Milvus multitenancy mode. This oversight permitted users to leverage unauthorized non-KB collection names as ephemeral collections, which were then processed without proper escaping, leading to exposure of sensitive resources.
Affected Version(s)
open-webui < 0.9.6
