Junglewise Threat Intelligence

CVE-2026-59225: Open WebUI authorization bypass in arena task endpoints

CVE-2026-59225 · Severity: medium · CVSS 5.4 · Published 2026-07-09

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI is an interface for interacting with AI models. A security flaw allows regular users to bypass access restrictions and query private or expensive AI models that administrators intended to keep restricted. This could lead to unauthorized data exposure, unexpected costs from paid AI providers, and the use of internal models by unauthorized personnel.

Technical details

A missing authorization check exists in Open WebUI's task endpoints, such as `/api/v1/tasks/moa/completions`. While the standard chat interface correctly validates access to underlying models within an 'arena' (a model wrapper used for comparisons), the task endpoints call the generation function directly. This direct path performs an access check on the arena wrapper but then uses a recursive call with `bypass_filter=True` to reach the selected sub-model, skipping its specific access controls. An authenticated attacker with read access to a public arena can thus query any restricted model contained within that arena. The issue was addressed in version 0.10.0.

Affected products

  • Open WebUI open-webui >= 0.8.12, < 0.10.0

Timeline

  • 2026-07-02: disclosed
  • 2026-07-24: advisory

References

Related threats