Executive brief
Open WebUI, a user interface for interacting with large language models, contains a flaw in its channel messaging system. Users who should only have permission to read messages are able to pin or unpin any message within a channel. This allows unauthorized users to disrupt the organization of information and highlight irrelevant content in shared workspaces.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the `pin_channel_message` API endpoint of Open WebUI. The root cause is an improper authorization check in `backend/open_webui/routers/channels.py` where the application validates 'read' permissions instead of 'write' permissions for a state-modifying operation. An authenticated attacker with read-only access to a standard channel can send a crafted POST request to the pin/unpin endpoint to modify the `is_pinned`, `pinned_by`, and `pinned_at` fields of any message. This bypasses intended access control grants. The issue is addressed in version 0.9.5 by updating the permission requirement to 'write'.
Affected products
- Open WebUI open-webui <= 0.9.4
Timeline
- 2026-05-10: disclosed
- 2026-05-14: advisory
- 2026-05-14: patched: Fixed in version 0.9.5