Executive brief
Open WebUI is an interface for interacting with large language models that includes group and direct messaging features. A security flaw allows users who have been removed from a chat channel to continue reading and posting messages by bypassing the user interface. This could lead to unauthorized access to sensitive conversations and a false sense of privacy for the remaining channel members.
Technical details
The vulnerability exists in the `is_user_channel_member` function within `backend/open_webui/models/channels.py`. This function checks for the existence of a membership record but fails to verify the `is_active` boolean field. Consequently, when a user leaves or is removed from a channel (setting `is_active` to False), the authorization check still returns True. An attacker with a valid account and knowledge of a previous channel ID can use direct API requests to message-level endpoints to read, post, edit, or delete messages. The issue is addressed in version 0.9.0 by adding the missing `is_active` check to the authorization logic.
Affected products
- Open WebUI open-webui <= 0.8.12
Timeline
- 2026-05-05: disclosed: Vulnerability reported by Classic298
- 2026-05-08: advisory: GitHub Advisory GHSA-hmgr-67hw-j2cq published
- 2026-05-08: patched: Fixed in version 0.9.0
- 2026-05-15: kev added: NVD published CVE-2026-44561