Cross-Origin Resource Sharing Misconfiguration in Open-WebUI Affects Multiple Versions
CVE-2026-56400

9CRITICAL

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 July 2026

What is CVE-2026-56400?

Open-WebUI versions before 0.3.14 suffer from a significant CORS misconfiguration that allows arbitrary origins due to the use of 'allow_origins=*'. This issue permits attackers to exploit the /api/v1/functions endpoint, enabling them to execute arbitrary code on the instance. The vulnerability arises when an admin user unknowingly interacts with malicious cross-site requests from compromised websites, effectively granting attackers unauthorized access to the system.

Affected Version(s)

open-webui 0 < 0.3.14

open-webui 0.3.14

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.