PT-2026-29571 · Unknown · Open-Webui

Timoles

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-34222

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI versions prior to 0.8.11
Description A broken access control issue exists in Open WebUI, specifically in tool values. This allows low-privileged attackers to access sensitive Tool data.
Recommendations Update to version 0.8.11 or later.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-34222
GHSA-7429-HXCV-268M

Affected Products

Open-Webui