Improper access control in Open WebUI - CVE-2026-45387

 

Improper access control in Open WebUI - CVE-2026-45387

Published: May 11, 2026


Vulnerability identifier: #VU130959
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45387
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the /api/v1/models/model endpoint when handling requests for model details by id. A remote user can send a request for a shared model identifier to disclose sensitive information.

The issue exposes the model's system prompt to users who were granted read access for model use.


Affected software

Open WebUI

How to mitigate CVE-2026-45387

Install security update from vendor's website.

Open WebUI - update to 0.9.5

External References

Related Security Bulletins