Open WebUI has Broken Access Control in Tool Valves
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.7epss 5.0%
exploitation probability
5.0%top 8% of all CVEs
observed exploitation
nono source reports it
In short
Open WebUI allows unauthorized users to access or modify tool settings that should be restricted to administrators. This means someone without proper permissions could change how AI tools behave, potentially accessing sensitive data or disrupting system functions.
Technical detail
A broken access control vulnerability in tool valves (CWE-285) permits authenticated or unauthenticated users to bypass authorization checks and read/modify tool configurations in Open WebUI versions prior to 0.8.11. The vulnerability affects the tool management endpoint, potentially allowing privilege escalation or unauthorized system manipulation without requiring elevated credentials.
Summary generated and translated by AI from the official description.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access control vulnerability in tool values. This issue has been patched in version 0.8.11.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected products
open-webui · open-webui