PT-2026-50488 · Unknown · Open-Webui
Hwwg
·
Published
2026-06-17
·
Updated
2026-06-23
·
CVE-2026-54016
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open WebUI versions prior to 0.9.6
Description
Open WebUI contains a Broken Object Level Authorization (BOLA) issue in the builtin
search knowledge files() function. BOLA occurs when an application does not properly verify if a user has permission to access a specific object via its ID. When native function calling is enabled and the selected model has no attached knowledge bases, an authenticated user can provide an arbitrary knowledge id variable to the search knowledge files() function. The system then returns file metadata from that knowledge base without verifying if the user has the required read access, allowing the unauthorized enumeration of private or restricted knowledge base files.Recommendations
Update to version 0.9.6.
As a temporary workaround, restrict the use of the
search knowledge files() function or disable native function calling until the update is applied.Exploit
Fix
IDOR
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open-Webui