Authorization bypass through user-controlled key in Open WebUI - CVE-2026-45385

 

Authorization bypass through user-controlled key in Open WebUI - CVE-2026-45385

Published: May 11, 2026


Vulnerability identifier: #VU130955
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45385
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify other users' messages.

The vulnerability exists due to improper access control in the update_message_by_id API endpoint when handling update requests for group or dm channels. A remote user can send a crafted update request for another member's message to modify other users' messages.

The issue affects the Channels feature and only applies when that feature is enabled. Messages posted by administrators within the same channel can also be modified.


Affected software

Open WebUI

How to mitigate CVE-2026-45385

Install security update from vendor's website.

Open WebUI - update to 0.9.5

External References

Related Security Bulletins