Junglewise Threat Intelligence

CVE-2026-45397: Open WebUI authentication bypass in RAG configuration endpoint

CVE-2026-45397 · Severity: medium · CVSS 5.3 · Published 2026-05-15

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI, a user interface for managing AI models, contains a security flaw that allows anyone on the internet to view sensitive configuration data without logging in. This data includes details about how the system processes documents and which AI engines are being used. An attacker can use this information to map out the internal infrastructure or craft more effective attacks against the AI's data retrieval process.

Technical details

A missing authentication check in the `get_status` function within `backend/open_webui/routers/retrieval.py` allows unauthenticated access to the `GET /api/v1/retrieval/` endpoint. While adjacent endpoints are protected by administrative user requirements, this specific route lacks the necessary dependency injection for user verification. An attacker can retrieve sensitive RAG pipeline details, including the `RAG_TEMPLATE`, embedding engine types, model names, and chunking parameters (`CHUNK_SIZE`, `CHUNK_OVERLAP`). This information facilitates infrastructure fingerprinting and enables precise RAG poisoning attacks by allowing attackers to calculate exact retrieval boundaries. The issue is addressed in version 0.9.5.

Affected products

  • Open WebUI Open WebUI < 0.9.5

Timeline

  • 2026-05-10: disclosed: Vulnerability reported by 0xRyuzak1
  • 2026-05-14: advisory
  • 2026-05-14: patched: Fixed in version 0.9.5

References

Related threats