Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-45339 — Open WebUI: API key endpoint restrictions bypassed via `x-api-key` header — full message …

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI allows admins to restrict which API endpoints an API key can access. When…

open_webui | Remote | Authorization
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
8.5 HIGH
CVE-2026-45331 — Open WebUI: Full SSRF Vulnerability in the RAG Web Search Feature

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, validate_url() in backend/open_webui/retrieval/web/utils.py calls validators.ipv6(ip…

open_webui | Remote | Server-Side Request Forgery
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
4.8 MEDIUM
CVE-2026-44568 — Open WebUI: Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the AccountPending.svelte component renders the admin-configured "Pending User Overl…

open_webui | Remote | Cross-Site Scripting
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
5.4 MEDIUM
CVE-2026-44564 — Open WebUI: Read-Only Users Can Modify Collaborative Documents via Socket.IO

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the ydoc:document:update Socket.IO event handler checks whether the sender is a memb…

open_webui | Remote | Authorization
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
5.4 MEDIUM
CVE-2026-44563 — Open WebUI: Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embedd…

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /api/generate, /api/embed, /api/embeddings, and /api/show endpoints accept any m…

open_webui | Remote | Authorization
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-44562 — Open WebUI: Model Import Overwrites Any Model Without Ownership Check

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import endpoint allows users with the workspace.models_impor…

open_webui | Remote | Authorization
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
5.4 MEDIUM
CVE-2026-44561 — Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the is_user_channel_member function checks whether a ChannelMember row exists but do…

open_webui | Remote | Authorization
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-44560 — Open WebUI: Unauthorized File and Knowledge Base Content Access via RAG Vector Search

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the type: "file" (non-full-context), type: "text" with collection_name, and bare col…

open_webui | Remote | Authorization
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
4.3 MEDIUM
CVE-2026-44559 — Open WebUI: Missing Access Check on Channel Members Endpoint for Standard Channels

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the GET /api/v1/channels/{id}/members endpoint only checks membership for group and …

open_webui | Remote | Authorization
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
5.4 MEDIUM
CVE-2026-44558 — Open WebUI: Channel Access Grants Bypass filter_allowed_access_grants

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the channel router does not call filter_allowed_access_grants on either create or up…

open_webui | Remote | Authorization
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
4.3 MEDIUM
CVE-2026-44557 — Open WebUI: Global Knowledge Base Enumeration via knowledge-bases Meta-Collection

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the _validate_collection_access function uses an incomplete allowlist that only enfo…

open_webui | Remote | Authorization
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
7.1 HIGH
CVE-2026-44556 — Open WebUI: responses passthrough endpoint lacks access control authorization

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the OpenAI router accepts any authenticated user and forw…

open_webui | Remote | Authorization
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
7.6 HIGH
CVE-2026-44555 — Open WebUI: Base Model Routing Bypasses Access Control via Model Chaining

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI supports model composition via base_model_id: a user-defined model (e.g.,…

open_webui | Remote | Authorization
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
8.1 HIGH
CVE-2026-44554 — Open WebUI: Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Over…

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/retrieval/process/web endpoint accepts a user-supplied collection_n…

open_webui | Remote | Authorization
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
8.1 HIGH
CVE-2026-44553 — Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User N…

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, administrative role changes and user deletions do not iterate SESSION_POOL to discon…

open_webui | Remote | Authentication
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
8.7 HIGH
CVE-2026-44552 — Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix En…

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the tool_servers and terminal_servers keys in utils/tools.py do use a prefix. When t…

open_webui | Remote | Misconfiguration
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
9.1 CRITICAL
CVE-2026-44551 — Open WebUI: LDAP Empty Password Authentication Bypass

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is no…

open_webui | Remote | Authentication
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
5.0 MEDIUM
CVE-2026-44550 — Open WebUI: Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other U…

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, FolderForm uses model_config = ConfigDict(extra='allow'), which permits arbitrary fi…

open_webui | Remote | Misconfiguration
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
6.3 MEDIUM
CVE-2025-67031 — ORSEE Remote Code Execution Vulnerability

ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnerability in the participant profile field processing subsystem. Certain field con…

Remote | Injection
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
9.1 CRITICAL
CVE-2026-8686 — DoS from MQTT v5.0 Deserialization Fault in core MQTT

Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet. To remediate this issue, users s…

coremqtt | Remote | Denial of Service
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
Showing 20 of 7213 Results