Missing Authorization in Open WebUI - CVE-2026-45350

 

Missing Authorization in Open WebUI - CVE-2026-45350

Published: May 11, 2026


Vulnerability identifier: #VU130943
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45350
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to invoke restricted tools and access their output.

The vulnerability exists due to missing authorization in the chat_completion API when processing user-supplied tool_ids or tool_servers parameters. A remote user can supply crafted tool identifiers to invoke restricted tools and access their output.

Requests can cause the server to use stored authentication tokens when invoking the selected tool.


Affected software

Open WebUI

How to mitigate CVE-2026-45350

Install security update from vendor's website.

Open WebUI - update to 0.8.6

External References

Related Security Bulletins