8.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Description
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/retrieval/process/web endpoint accepts a user-supplied collection_name and an overwrite query parameter (default: True). It performs no authorization check on whether the calling user owns or has write access to the target collection. When overwrite=True, save_docs_to_vector_db calls VECTOR_DB_CLIENT.delete_collection() on the target collection before writing new content. This vulnerability is fixed in 0.9.0.
Basic Information
ID
CVE-2026-44554
Source
GitHub_M
Published
May 15, 2026 at 19:49
Modified
May 15, 2026 at 21:09
Affected Product
Vendor
open-webui
Product
open-webui
Version
< 0.9.0
Affected Versions
open-webui open-webui < 0.9.0