PT-2026-41183 · Unknown · Open-Webui

CVE-2026-45365

·

Published

2026-03-26

·

Updated

2026-07-13

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI versions prior to 0.8.11
Description An internal-only bypass filter parameter is exposed on the '/openai/chat/completions' and '/ollama/api/chat' HTTP endpoints due to FastAPI query string binding. This allows any authenticated user to append ?bypass filter=true to the request URL, skipping model access control checks and enabling the invocation of admin-restricted models using the server's API keys.
Recommendations Update to version 0.8.11 or later.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07440
CVE-2026-45365
GHSA-V6QF-75PR-P96M
PYSEC-2026-2758

Affected Products

Open-Webui