Junglewise Threat Intelligence

CVE-2026-54016: Open WebUI BOLA in search_knowledge_files tool

CVE-2026-54016 · Severity: medium · CVSS 4.3 · Published 2026-06-23

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI is a self-hosted platform for running artificial intelligence models locally. A security flaw in the platform's search tool allows logged-in users to view metadata for private files they are not authorized to see. This could lead to the exposure of sensitive information contained in filenames, such as financial reports or internal project names, potentially compromising organizational privacy.

Technical details

A Broken Object Level Authorization (BOLA) vulnerability exists in the `search_knowledge_files` tool within `backend/open_webui/tools/builtin.py`. When native function calling is enabled and a model has no attached knowledge bases, the application fails to validate if the requesting user has read permissions for a manually provided `knowledge_id`. An authenticated attacker can exploit this by calling the tool with a known `knowledge_id` to retrieve file metadata, including filenames and file IDs, from restricted knowledge bases. The underlying `Knowledges.search_files_by_id` method does not enforce authorization, bypassing the AccessGrants permission model. This issue is resolved in version 0.9.6.

Affected products

  • Open WebUI Open WebUI < 0.9.6

Timeline

  • 2026-06-11: advisory: GitHub Security Advisory published by maintainers.
  • 2026-06-23: disclosed: CVE published to NVD.
  • 2026-06-23: patched: Fix confirmed in version 0.9.6.

References

Related threats