Missing Authorization in Open WebUI - CVE-2026-45350
Published: May 11, 2026
Vulnerability details
The vulnerability allows a remote user to invoke restricted tools and access their output.
The vulnerability exists due to missing authorization in the chat_completion API when processing user-supplied tool_ids or tool_servers parameters. A remote user can supply crafted tool identifiers to invoke restricted tools and access their output.
Requests can cause the server to use stored authentication tokens when invoking the selected tool.