Missing Authorization in Open WebUI - #VU130175
Published: May 5, 2026
Open WebUI
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the GET /api/v1/channels/{id}/members endpoint when handling requests for standard channels. A remote user can send a request for a private channel's member list to disclose sensitive information.
Channels must be enabled, and exploitation requires knowledge of the target channel UUID.