Improper access control in Open WebUI - CVE-2026-44552

 

Improper access control in Open WebUI - CVE-2026-44552

Published: May 5, 2026


Vulnerability identifier: #VU130164
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44552
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to poison shared cache data across instances and disclose sensitive information.

The vulnerability exists due to improper access control in the tool server and terminal server Redis cache in backend/open_webui/utils/tools.py when multiple instances share a Redis backend. A remote privileged user can write attacker-controlled tool server or terminal server entries to unprefixed Redis keys to poison shared cache data across instances and disclose sensitive information.

Exploitation requires multiple Open WebUI instances to share a single Redis backend.


Affected software

Open WebUI

How to mitigate CVE-2026-44552

Install security update from vendor's website.

Open WebUI - update to 0.9.0

External References

Related Security Bulletins