PT-2026-28711 · Wandb · Wandb/Openui
Eric-B
+1
·
Published
2026-03-28
·
Updated
2026-03-28
·
CVE-2026-4993
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
wandb OpenUI versions up to 0.0.0.0/1.0
Description
A security issue exists in wandb OpenUI related to hard-coded credentials. The manipulation of the
LITELLM MASTER KEY argument within the file backend/openui/config.py can lead to exposure of these credentials. The exploit is publicly available and requires local access to initiate an attack. The vendor was informed of this issue but did not respond.Recommendations
Versions prior to 0.0.0.0/1.0 should be updated. As a temporary workaround, consider restricting access to the
backend/openui/config.py file to minimize the risk of exploitation.Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wandb/Openui