CVE Explorer
CVE-2026-45339
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI allows admins to restrict which API endpoints an API key can access. When an API key is restricted from /api/v1/messages, requests using the Authorization: Bearer sk-... header are correctly blocked with 403. However, the same key sent via the x-api-key header bypasses the restriction entirely — the request is authenticated, the model is invoked, and a full response is re
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"open-webui","vendor":"open-webui","versions":[{"status":"affected","version":"< 0.9.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d7c217b683f80ee224399383c7444a9579a5487348474c7a389ea08a6543770c · sha256:c41eea5cd5429ab5… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d7c217b683f80ee224399383c7444a9579a5487348474c7a389ea08a6543770c · sha256:c41eea5cd5429ab5… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d7c217b683f80ee224399383c7444a9579a5487348474c7a389ea08a6543770c · sha256:c41eea5cd5429ab5… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/open-webui/open-webui/security/advisories/GHSA-57q6-fvp4-pqmm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-57q6-fvp4-pqmm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d7c217b683f80ee224399383c7444a9579a5487348474c7a389ea08a6543770c · sha256:c41eea5cd5429ab5… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-57q6-fvp4-pqmm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d7c217b683f80ee224399383c7444a9579a5487348474c7a389ea08a6543770c · sha256:c41eea5cd5429ab5… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.