Missing Authorization in Open WebUI - #VU152714
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to manage terminal policies and other users' terminals.
The vulnerability exists due to missing authorization in the terminal proxy endpoint in backend/open_webui/routers/terminals.py when forwarding requests to Terminals administrator API paths. A remote user can send requests for administrator API paths through the terminal proxy to manage terminal policies and other users' terminals.
Exploitation requires access to an unpinned Terminals connection configured with bearer authentication.