Improper access control in Open WebUI - CVE-2026-44560

 

Improper access control in Open WebUI - CVE-2026-44560

Published: May 5, 2026


Vulnerability identifier: #VU130174
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44560
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in get_sources_from_items in the RAG source resolution logic when processing chat completion requests that reference file or knowledge base vector collections. A remote user can send a specially crafted chat completion request referencing a target file ID or knowledge base collection name to disclose sensitive information.

Exploitation requires knowledge of the target file ID or knowledge base ID, and the target resource must already be processed into the vector store.


Affected software

Open WebUI

How to mitigate CVE-2026-44560

Install security update from vendor's website.

Open WebUI - update to 0.9.0

External References

Related Security Bulletins