Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access control vulnerability in tool values. This issue has been patched in version 0.8.11.
References
Configurations
No configuration.
History
03 Apr 2026, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Apr 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-01 18:16
Updated : 2026-04-03 16:10
NVD link : CVE-2026-34222
Mitre link : CVE-2026-34222
CVE.ORG link : CVE-2026-34222
JSON object : View
Products Affected
No product.
CWE
CWE-285
Improper Authorization
