Authorization bypass through user-controlled key in Open WebUI - CVE-2026-44570

 

Authorization bypass through user-controlled key in Open WebUI - CVE-2026-44570

Published: May 6, 2026


Vulnerability identifier: #VU130242
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44570
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify other users' memories.

The vulnerability exists due to improper access control in the memories API when handling requests to memory query, update, and delete endpoints. A remote user can send crafted API requests using another user's memory identifier to disclose sensitive information and modify other users' memories.

The issue can expose memory contents and associated user ID values, and deleted memories can be restored through the update endpoint.


Affected software

Open WebUI

How to mitigate CVE-2026-44570

Install security update from vendor's website.

Open WebUI - update to 0.6.19

External References

Related Security Bulletins