Improper Authorization in Open WebUI - CVE-2026-34222

 

Improper Authorization in Open WebUI - CVE-2026-34222

Published: April 24, 2026


Vulnerability identifier: #VU127478
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34222
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper authorization in the Tool Valves endpoint when handling requests to read tool valve data. A remote user can send a crafted request for a tool valve to disclose sensitive information.

Exploitation requires a verified account with at least Member privileges, and tool identifiers are trivial to guess because imported tool IDs are derived from tool names.


Affected software

Open WebUI

How to mitigate CVE-2026-34222

Install security update from vendor's website.

Open WebUI - update to 0.8.11

External References

Related Security Bulletins