CVE-2026-44551Disclosure(openwebui / open_webui)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch openwebui open_webui systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is non-empty before performing a Simple Bind against the LDAP server. The LdapForm Pydantic model accepts password: str with no minimum length constraint, so an empty string passes validation. The subsequent Connection.bind() call succeeds on vulnerable LDAP servers, and the application issues a full session token for the target user. This vulnerability is fixed in 0.9.0.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open_webui

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-16); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
open_webui

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-05-08: 1Mentions · 2026-05-09: 1Mentions · 2026-05-10: 1Mentions · 2026-05-16: 2Mentions · 2026-05-19: 1Active Exploitation · 2026-05-08: 1Active Exploitation · 2026-05-10: 1Patch / Workaround · 2026-05-09: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-16: 1Technical Details · 2026-05-19: 105-0805-0905-1005-1605-19
Signal classification2 categories
Disclosure
583.3%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-081
Active Exploitation1
2026-05-091
Disclosure1
2026-05-101
Disclosure1
2026-05-162
Disclosure2
2026-05-191
Disclosure1
Full discourse6 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-44551 (CVSS 9.1) + CVE-2026-45672 (CVSS 8.8): LDAP empty-password bind and verified-user code execution bypass on exposed AI consoles 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJPcGVuLVdlYlVJIg%3D%3D 🎯137.4K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Open-WebUI" 🔖Refer: https://github.com/open-webui/open-webui/security/advisories/GHSA-2r4p-jpmg-48f4 #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    CVE-2026-44551 and CVE-2026-45672 are disclosed as high‑severity LDAP and code execution vulnerabilities on AI consoles, with detailed CVSS scores and links to FOFA data and a GitHub advisory.

    0702022.2K
    14.4K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Open WebUI LDAP authentication bypass (CVE-2026-44551) Open WebUI fails to validate non-empty passwords before performing LDAP Simple Bind authentication. On LDAP servers that permit unauthenticated empty-password binds, attackers can authenticate as any valid LDAP user - including admins - without knowing credentials, resulting in full account takeover. 👉 Affected: <= 0.8.12 | Fix: 0.9.0

    Post summary

    The post announces a critical LDAP authentication bypass (CVE‑2026‑44551) in Open WebUI, detailing the flaw and providing a fix version (0.9.0).

    0002099
    245 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-44551 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate … https://www.cve.org/CVERecord?id=CVE-2026-44551 ----- Traducción: CVE-2026-44551 Ope… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑44551 for Open WebUI’s LDAP authentication, linking to the official CVE record, but offers no exploit, patch, or technical details.

    0000037
    78 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44551 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate … https://www.cve.org/CVERecord?id=CVE-2026-44551

    Post summary

    The post announces CVE‑2026‑44551, noting a lack of validation in Open WebUI's LDAP authentication before 0.9.0, but offers no PoC, exploit, patch, or active exploitation details.

    00000229
    57.5K followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Disclosure

    In the last two weeks: Ollama leaks API keys via an unauth file upload endpoint (CVE-2026-7482). Open WebUI accepts empty LDAP passwords (CVE-2026-44551). LiteLLM stored API keys in a SQL-injectable database — CISA added it to KEV (CVE-2026-42208).

    Post summary

    The text announces three new CVEs, detailing how each flaw can be exploited, and notes that one has already been listed by CISA as a known exploited vulnerability.

    00000463
    34 followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Active Exploitation

    Today (Fri, May 8): 1 KEV, 6 critical CVEs. LiteLLM SQLi (KEV) earlier. Long tail: - Open WebUI: 7 advisories, LDAP empty-password bypass (CVE-2026-44551, 9.1) - Electerm SSH client: 4 RCE-class bugs (CVE-2026-43940, 9.8) - PrestaShop stored XSS (CVE-2026-44212, 9.3)

    Post summary

    The post highlights several critical CVEs, noting a known exploitation for LiteLLM SQLi and listing vulnerabilities for Open WebUI, Electrum SSH client, and PrestaShop, but provides no PoC, exploit tool, or patch details.

    0000077
    34 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenwebuiopen_webui---

Explore more