CVE-2026-45301Disclosure(openwebui / open_webui)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch openwebui open_webui systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.3.16, a missing permission check in all files related API endpoints allows any authenticated user to list, access and delete every file uploaded by every user to the platform. This vulnerability is fixed in 0.3.16.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open_webui

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
open_webui

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-16: 2Patch / Workaround · 2026-05-16: 1Technical Details · 2026-05-16: 205-16
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-45301 Unauthorized File Access and Deletion in Open WebUI Prior to 0.3.16 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45301

    Post summary

    The post simply announces CVE-2026-45301 with a brief description of unauthorized file access and deletion, providing no evidence of PoC, exploit, or patch.

    0000085
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-45301 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.3.16, a missing permission check in all files related AP… https://www.cve.org/CVERecord?id=CVE-2026-45301

    Post summary

    The post discloses a missing permission‑check vulnerability in Open WebUI, which is fixed in v0.3.16, with no PoC, active exploitation, or debunking details provided.

    00000149
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenwebuiopen_webui---

Explore more