Improper Authorization in Open WebUI - CVE-2026-34222
Published: April 24, 2026
Open WebUI
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper authorization in the Tool Valves endpoint when handling requests to read tool valve data. A remote user can send a crafted request for a tool valve to disclose sensitive information.
Exploitation requires a verified account with at least Member privileges, and tool identifiers are trivial to guess because imported tool IDs are derived from tool names.