Executive brief
Open WebUI is an interface for interacting with AI models. A security flaw in the channel management system allows regular users to bypass administrative restrictions and make private chat channels public. This could lead to unauthorized access to sensitive conversations and data by any user on the platform, undermining the organization's data privacy policies.
Technical details
A missing authorization check in the channel router allows users to bypass the 'filter_allowed_access_grants' function. While other resource types (models, prompts, etc.) correctly filter access grants to prevent unauthorized public sharing, the channel creation and update endpoints in 'backend/open_webui/routers/channels.py' do not. An authenticated attacker can submit a wildcard access grant (principal_id: '*') to make a channel publicly readable, even if the administrator has disabled public channel sharing for regular users. This vulnerability is rooted in CWE-862 (Missing Authorization) and CWE-863 (Incorrect Authorization). A fix is available in version 0.9.0.
Affected products
- Open WebUI open-webui <= 0.8.12
Timeline
- 2026-05-05: disclosed: Vulnerability reported by Classic298
- 2026-05-08: advisory: GitHub Advisory GHSA-7rjh-px4v-5w55 published
- 2026-05-08: patched: Fixed in version 0.9.0