CVE-2026-44553
- EPSS 0.28%
- Veröffentlicht 15.05.2026 19:54:09
- Zuletzt bearbeitet 19.05.2026 14:16:44
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, administrative role changes and user deletions do not iterate SESSION_POOL to disconnect affected sessions. As a result, a user whose a...
CVE-2026-44554
- EPSS 0.3%
- Veröffentlicht 15.05.2026 19:49:55
- Zuletzt bearbeitet 19.05.2026 03:12:09
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/retrieval/process/web endpoint accepts a user-supplied collection_name and an overwrite query parameter (default: True...
CVE-2026-44555
- EPSS 0.25%
- Veröffentlicht 15.05.2026 19:48:35
- Zuletzt bearbeitet 19.05.2026 03:12:26
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI supports model composition via base_model_id: a user-defined model (e.g., "Cheap Assistant") can reference an existing base ...
CVE-2026-44556
- EPSS 0.31%
- Veröffentlicht 15.05.2026 19:46:17
- Zuletzt bearbeitet 19.05.2026 03:12:44
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the OpenAI router accepts any authenticated user and forwards requests directly to upstream LLM providers wi...
CVE-2026-44557
- EPSS 0.22%
- Veröffentlicht 15.05.2026 19:44:49
- Zuletzt bearbeitet 19.05.2026 03:13:19
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the _validate_collection_access function uses an incomplete allowlist that only enforces ownership checks for collections matching user...
CVE-2026-44558
- EPSS 0.19%
- Veröffentlicht 15.05.2026 19:43:40
- Zuletzt bearbeitet 19.05.2026 14:16:44
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the channel router does not call filter_allowed_access_grants on either create or update paths. A non-admin user who can create group c...
CVE-2026-44559
- EPSS 0.22%
- Veröffentlicht 15.05.2026 19:41:59
- Zuletzt bearbeitet 19.05.2026 03:09:30
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the GET /api/v1/channels/{id}/members endpoint only checks membership for group and dm channel types (lines 467-469). For standard chan...
CVE-2026-44560
- EPSS 0.37%
- Veröffentlicht 15.05.2026 19:40:51
- Zuletzt bearbeitet 19.05.2026 03:09:56
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the type: "file" (non-full-context), type: "text" with collection_name, and bare collection_name/collection_names paths in the get_sour...
CVE-2026-44561
- EPSS 0.18%
- Veröffentlicht 15.05.2026 19:34:52
- Zuletzt bearbeitet 19.05.2026 03:10:26
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the is_user_channel_member function checks whether a ChannelMember row exists but does not check the is_active field. When a user is de...
CVE-2026-44562
- EPSS 0.29%
- Veröffentlicht 15.05.2026 19:30:40
- Zuletzt bearbeitet 19.05.2026 03:10:46
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import endpoint allows users with the workspace.models_import permission to overwrite any existing model in the...