Authorization bypass through user-controlled key in Open WebUI - #VU152711
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to disclose directory structure information from inaccessible knowledge bases.
The vulnerability exists due to authorization bypass through a user-controlled key in knowledge base directory handling endpoints when submitting a directory id from a different knowledge base. A remote user can send a request containing a foreign directory id to disclose directory structure information from inaccessible knowledge bases.
Exploitation requires knowledge of a directory id in a knowledge base to which the user does not have access.