Junglewise Threat Intelligence

CVE-2026-45365: Open WebUI authorization bypass in OpenAI and Ollama endpoints

CVE-2026-45365 · Severity: medium · CVSS 5.4 · Published 2026-05-15

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI is a user interface for interacting with Large Language Models (LLMs). A security flaw allows any logged-in user to bypass restrictions set by administrators on which AI models they can use. By adding a specific parameter to their web requests, users can access expensive or restricted models that they are not authorized to use, potentially leading to unauthorized costs or data access.

Technical details

A vulnerability exists in the OpenAI and Ollama proxy endpoints of Open WebUI due to the exposure of an internal-only 'bypass_filter' parameter in the FastAPI route handlers. Because FastAPI automatically binds function parameters to query strings, authenticated users can append '?bypass_filter=true' to requests sent to '/openai/chat/completions' or '/ollama/api/chat'. This causes the backend to skip Access Control List (ACL) checks, enabling users to invoke any configured model, including those restricted to administrators. The issue was resolved in version 0.8.11 by moving the parameter to the internal request state where it cannot be influenced by external HTTP inputs.

Affected products

  • Open WebUI open-webui <= 0.8.10

Timeline

  • 2026-03-20: patched: Fixed in commit c0385f60b and released in v0.8.11.
  • 2026-05-10: disclosed: Initial disclosure on GitHub.
  • 2026-05-14: advisory: Advisory updated and published.

References

Related threats