2026-07-10NOTABLECSA Labs shows self-hosted Open WebUI has shipped six access-control CVEs since November 2025, including an XSS-to-RCE chain and one still-unpatched IDOR
Open WebUI incomplete collection allowlist exposes knowledge-base metadata to any user
cve · CVE-2026-44557
Coverage
1
first 2026-07-10 → last 2026-07-10
Latest activity
2026-07-10
CSA Labs shows self-hosted Open WebUI has shipped six access-control CVEs since November 2025, including an…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, education, technology
Sources cited
3
2 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-44557, newest first. Check the date before acting on an older one.
- Confirm Open WebUI instances run ≥ 0.9.6; audit which accounts hold the workspace.tools permission and revoke it from any account not authoring executable functions, that permission is what converts client-side token theft into server-side RCE.2026-07-10CVE-2025-64496 +5
- Restrict the Direct Connections feature to fully-trusted model servers only, and place the Open WebUI admin interface and API behind an authenticating reverse proxy / SSO gateway / VPN rather than exposing it directly; CVE-2025-63681 has no patch, so a compensating control is the only mitigation for it.2026-07-10CVE-2025-64496 +5
Defender insights
What each entry about CVE-2026-44557 tells a defender to do, newest first.
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (4 across 3 tactics)
4 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter: Python · Command and Scripting Interpreter: JavaScript
- Credential AccessSteal Web Session Cookie
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-10/open-webui-recurring-broken-access-control-cve-cluster · ATT&CK page ↗
Execution TA0002
T1059.006Command and Scripting Interpreter: Python×1
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.
Evidence: 2026-07-10/open-webui-recurring-broken-access-control-cve-cluster · ATT&CK page ↗
T1059.007Command and Scripting Interpreter: JavaScript×1
Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.
Evidence: 2026-07-10/open-webui-recurring-broken-access-control-cve-cluster · ATT&CK page ↗
Credential Access TA0006
T1539Steal Web Session Cookie×1
An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.
Evidence: 2026-07-10/open-webui-recurring-broken-access-control-cve-cluster · ATT&CK page ↗
Entries about Open WebUI incomplete collection allowlist exposes knowledge-base metadata to any user (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Open WebUI×1
- Open WebUI /api/openai/responses proxy reaches any model without per-model authz×1
- Open WebUI /api/tasks/stop/ IDOR, unauthorized task cancellation (unpatched)×1
- Open WebUI Direct Connections XSS chained to unsandboxed Python exec() → RCE×1
- Open WebUI prompt version-history IDOR (caller-supplied history-ID unauthorized)×1
- Open WebUI Socket.IO ydoc:document:update checks room membership not write permission×1
Where this entity is cited
Source distribution
- github.com2 (67%)
- labs.cloudsecurityalliance.org1 (33%)
External references
All cited sources (3)
- labs.cloudsecurityalliance.orgprimaryCloud Security Alliance (CSA Labs)https://labs.cloudsecurityalliance.org/research/csa-research-note-open-webui-access-control-cves-20260710-cs/
- github.comGitHub Security Advisorieshttps://github.com/advisories/GHSA-4r4w-2wgp-w7cj
- github.comGitHub Security Advisorieshttps://github.com/advisories/GHSA-hp5m-24vp-vq2q