Cross-Origin Resource Sharing Misconfiguration in Open-WebUI Affects Multiple Versions
CVE-2026-56400
9CRITICAL
What is CVE-2026-56400?
Open-WebUI versions before 0.3.14 suffer from a significant CORS misconfiguration that allows arbitrary origins due to the use of 'allow_origins=*'. This issue permits attackers to exploit the /api/v1/functions endpoint, enabling them to execute arbitrary code on the instance. The vulnerability arises when an admin user unknowingly interacts with malicious cross-site requests from compromised websites, effectively granting attackers unauthorized access to the system.
Affected Version(s)
open-webui 0 < 0.3.14
open-webui 0.3.14
