PT-2026-39273 · Unknown · Open-Webui

Published

2026-05-08

·

Updated

2026-05-16

·

CVE-2026-44556

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Open WebUI versions prior to 0.9.0
Description The '/responses' endpoint in the OpenAI router allows any authenticated user to forward requests to upstream LLM providers without enforcing per-model access control. While the generate chat completion() function validates model ownership, group membership, and AccessGrants, the '/responses' proxy only verifies the user session via get verified user(). Consequently, an authenticated user can interact with any configured model by sending a POST request to '/api/openai/responses' using an arbitrary model ID. This can lead to Model Denial of Service by exhausting API budgets or rate limits through resource-intensive models, and Model Theft via unauthorized interaction with fine-tuned or self-hosted models, effectively bypassing administrative access policies.
Recommendations Update to version 0.9.0.

Fix

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-44556
GHSA-HP5M-24VP-VQ2Q

Affected Products

Open-Webui