CVE-2026-45398Disclosure(openwebui / open_webui)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, _validate_collection_access() checks the user-memory-* and file-* collection name prefixes but does not check knowledge base collections, which use raw UUIDs as collection names. Any authenticated user who knows a private knowledge base UUID can read its content through the retrieval query endpoints, even though the knowledge API correctly denies that user access. The same gap affects the retrieval write endpoints (/process/text, /process/file, /process/files/batch, /process/web, /process/youtube), allowing an attacker to inject content into or overwrite another user's knowledge base. This vulnerability is fixed in 0.9.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open_webui

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-15); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
open_webui

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-15: 1Mentions · 2026-05-16: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-16: 105-1505-16
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-45398 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, _validate_collection_access() checks the user-memor… https://www.cve.org/CVERecord?id=CVE-2026-45398

    Post summary

    This statement announces CVE‑2026‑45398 for Open WebUI, noting a security check deficit before version 0.9.5, but provides no PoC, exploit, or patch details.

    00000228
    57.5K followersView on X
  • Israel@f1tym1
    Disclosure

    Open WebUI Multiple Vulnerabilities https://ift.tt/25UmDYK Open WebUI Multiple Vulnerabilities CVE-2026-45398 - IDOR: Retrieval API Bypasses Knowledge Base Access Controls Summary _validate_collection_access() (PR #22109) checks the user-memory-* and file-* collection name …

    Post summary

    The post announces the discovery of an Indirect Data Retrieval (IDOR) vulnerability (CVE-2026-45398) in Open WebUI's Retrieval API, providing a brief technical description but no PoC, exploit, patch, or evidence of active exploitation.

    0000038
    971 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenwebuiopen_webui---

Explore more