Executive brief
Open WebUI is a self-hosted interface for interacting with artificial intelligence models. A security flaw in how the system handles data queries allows logged-in users to bypass access controls and view private information belonging to other users. This could lead to the unauthorized exposure of sensitive documents or knowledge bases stored within the platform.
Technical details
A vulnerability exists in Open WebUI's RAG implementation when configured with Milvus in multitenancy mode. The application fails to properly sanitize collection names before interpolating them into Milvus expressions, leading to a query logic injection (CWE-943). Specifically, the ACL logic permits unknown collection names as 'legacy' collections, and these user-controlled strings are inserted into a 'resource_id' field without escaping. An authenticated attacker can provide a crafted collection name containing SQL-like logic (e.g., using single quotes and OR conditions) to bypass intended filters and retrieve private data chunks from other users' collections. This is an incomplete fix for CVE-2026-44560 and is addressed in version 0.9.6.
Affected products
- open-webui open-webui < 0.9.6
Timeline
- 2026-06-11: advisory: GitHub Security Advisory published
- 2026-06-23: disclosed: CVE published to NVD
- 2026-06-23: patched: Fixed in version 0.9.6