
⚠️⚠️ CVE-2026-44551 (CVSS 9.1) + CVE-2026-45672 (CVSS 8.8): LDAP empty-password bind and verified-user code execution bypass on exposed AI consoles 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJPcGVuLVdlYlVJIg%3D%3D 🎯137.4K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Open-WebUI" 🔖Refer: https://github.com/open-webui/open-webui/security/advisories/GHSA-2r4p-jpmg-48f4 #OSINT #FOFA #CyberSecurity #Vulnerability
Post summary
The post announces two newly disclosed CVEs with technical details and provides OSINT results and advisory references, but does not present PoC code, exploitation evidence, or mitigation information.

