Improper access control in Open WebUI - CVE-2026-44558

 

Improper access control in Open WebUI - CVE-2026-44558

Published: May 5, 2026


Vulnerability identifier: #VU130168
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44558
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify access permissions.

The vulnerability exists due to improper access control in the channel creation and update endpoints when handling access_grants during channel creation or update requests. A remote user can submit crafted access grants to disclose sensitive information and modify access permissions.

Exploitation requires an account that can create group channels or ownership of an existing channel, and restrictive sharing permissions must be configured for regular users.


Affected software

Open WebUI

How to mitigate CVE-2026-44558

Install security update from vendor's website.

Open WebUI - update to 0.9.0

External References

Related Security Bulletins