Junglewise Threat Intelligence

CVE-2026-44563: Open WebUI missing authorization in Ollama proxy endpoints

CVE-2026-44563 · Severity: medium · CVSS 5.4 · Published 2026-05-15

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI is a user interface for interacting with AI models. A security flaw allows authenticated users to bypass administrative restrictions and access AI models they are not authorized to use. This could lead to unauthorized use of expensive computing resources (GPU) and the exposure of sensitive model configurations, such as system prompts and internal parameters.

Technical details

A missing authorization check (CWE-862) exists in the Ollama proxy router of Open WebUI. While the '/api/chat' endpoint correctly validates model access grants, the '/api/generate', '/api/embed', '/api/embeddings', and '/api/show' endpoints only verify that a user is authenticated. They fail to call 'AccessGrants.has_access()', allowing any logged-in user to bypass group-based or user-based restrictions if they know the target model's name. An attacker can use these endpoints to perform inference on restricted models or retrieve sensitive metadata via the '/api/show' endpoint. The issue is addressed in version 0.9.0.

Affected products

  • Open WebUI Open WebUI <= 0.8.12

Timeline

  • 2026-05-05: disclosed: Initial report to open-webui/open-webui
  • 2026-05-08: advisory: GitHub Advisory published
  • 2026-05-15: patched: NVD publication and patch availability confirmed in 0.9.0

References

Related threats