Improper Authentication in Open WebUI - CVE-2026-44551

 

Improper Authentication in Open WebUI - CVE-2026-44551

Published: May 5, 2026


Vulnerability identifier: #VU130171
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44551
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication and gain access to another user's account.

The vulnerability exists due to improper authentication in the LDAP authentication endpoint when processing LDAP login requests with an empty password. A remote attacker can submit a valid LDAP username and an empty password to bypass authentication and gain access to another user's account.

Exploitation requires LDAP authentication to be enabled, the underlying LDAP server to accept unauthenticated simple binds with empty passwords, and knowledge of a valid LDAP username.


Affected software

Open WebUI

How to mitigate CVE-2026-44551

Install security update from vendor's website.

Open WebUI - update to 0.9.0

External References

Related Security Bulletins