Access Control Flaw in Open WebUI Artificial Intelligence Platform
CVE-2026-54021
6.3MEDIUM
What is CVE-2026-54021?
The Open WebUI platform, a self-hosted AI solution, has a security issue where an authenticated user can manipulate the url_idx parameter to access unauthorized backends. This flaw allows users to redirect their requests to internal or privileged backends, circumventing intended access limitations. The issue has been resolved in version 0.9.6.
Affected Version(s)
open-webui < 0.9.6
