PT-2026-39274 · Unknown · Open-Webui

Published

2026-05-08

·

Updated

2026-05-16

·

CVE-2026-44557

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI versions prior to 0.9.0
Description The validate collection access() function employs an incomplete allowlist that only verifies ownership for collections starting with user-memory-* and file-*. Other collection names, such as the system-level knowledge-bases meta-collection, are not checked. This allows any authenticated user to query the meta-collection via retrieval query endpoints, such as 'POST /api/v1/retrieval/query/doc', using the collection name parameter to obtain a global index of all knowledge bases across all users, including their IDs, names, and descriptions.
Recommendations Update to version 0.9.0.

Fix

Missing Authorization

Incorrect Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-44557
GHSA-6C2X-GCP3-GP73

Affected Products

Open-Webui