CVE-2026-44562

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import endpoint allows users with the workspace.models_import permission to overwrite any existing model in the database, regardless of ownership. When an imported model's ID matches an existing model, the endpoint merges the attacker's payload over the existing model data and writes it to the database with no ownership or access grant validation. Additionally, filter_allowed_access_grants is never called, bypassing the access grant restrictions enforced on all other model mutation endpoints. This vulnerability is fixed in 0.9.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*

History

19 May 2026, 03:10

Type Values Removed Values Added
First Time Openwebui
Openwebui open Webui
CPE cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*
References () https://github.com/open-webui/open-webui/security/advisories/GHSA-mqq6-cqcx-38vg - () https://github.com/open-webui/open-webui/security/advisories/GHSA-mqq6-cqcx-38vg - Exploit, Vendor Advisory

15 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-15 20:16

Updated : 2026-05-19 03:10


NVD link : CVE-2026-44562

Mitre link : CVE-2026-44562

CVE.ORG link : CVE-2026-44562


JSON object : View

Products Affected

openwebui

  • open_webui
CWE
CWE-283

Unverified Ownership

CWE-862

Missing Authorization