Missing Authorization in Open WebUI - #VU152714

 

Missing Authorization in Open WebUI - #VU152714

Published: September 28, 2026


Vulnerability identifier: #VU152714
CSH Severity: Low
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to manage terminal policies and other users' terminals.

The vulnerability exists due to missing authorization in the terminal proxy endpoint in backend/open_webui/routers/terminals.py when forwarding requests to Terminals administrator API paths. A remote user can send requests for administrator API paths through the terminal proxy to manage terminal policies and other users' terminals.

Exploitation requires access to an unpinned Terminals connection configured with bearer authentication.


Affected software

Open WebUI

Remediation

Install security update from vendor's website.

Open WebUI - update to 0.11.4

External References

Related Security Bulletins