---
schema: 1
kind: research
title: "Open WebUI's six broken-access-control CVEs are one recurring authorization-architecture defect, not six isolated bugs"
headline: "CSA Labs shows self-hosted Open WebUI has shipped six access-control CVEs since November 2025 — including an XSS-to-RCE chain and one still-unpatched IDOR"
summary: >
  A Cloud Security Alliance research note synthesizes six distinct broken-access-control CVEs disclosed in
  the self-hosted Open WebUI LLM front-end between November 2025 and June 2026 into one architectural
  pattern: authorization decided ad hoc per endpoint rather than through a central policy layer. The most
  severe (CVE-2025-64496) chains a Direct Connections client-side flaw with unsandboxed Python tool
  execution to reach RCE on the host; one CVE (CVE-2025-63681) remains unpatched. Teams self-hosting
  Open WebUI — common in public-sector and research environments keeping LLM data off SaaS — should
  confirm they run ≥ 0.9.6 and audit the workspace.tools permission.
discovered_at: "2026-07-10T20:34:32Z"
event_date: "2026-07-10"
run_id: 2026-07-10T2009Z-intel
priority: notable
immediate_action: null
tags: [vulnerabilities, cloud, ai-abuse, rce, auth-bypass, info-disclosure, no-patch, patch-available]
regions: [global]
sectors: [public-sector, education, technology]
entities: []
techniques: [T1190, T1059.007, T1059.006, T1539]
affected_products: ["Open WebUI"]
cves:
  - id: CVE-2025-64496
    cvss: "7.3"
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status: [patch-available]
    affected: "≤ 0.6.34"
    fixed: "0.6.35"
  - id: CVE-2026-44556
    cvss: "7.1"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "≤ 0.8.12"
    fixed: "0.9.0"
  - id: CVE-2026-54015
    cvss: "6.4"
    epss: null
    type: info-disclosure
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "≤ 0.9.5"
    fixed: "0.9.6"
  - id: CVE-2026-44564
    cvss: "5.4"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "≤ 0.8.12"
    fixed: "0.9.0"
  - id: CVE-2026-44557
    cvss: "4.3"
    epss: null
    type: info-disclosure
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "≤ 0.8.12"
    fixed: "0.9.0"
  - id: CVE-2025-63681
    cvss: "2.1"
    epss: null
    type: dos
    vector: zero-click
    auth: post-auth
    status: [no-patch]
    affected: "all versions"
    fixed: "none"
sources:
  - url: "https://labs.cloudsecurityalliance.org/research/csa-research-note-open-webui-access-control-cves-20260710-cs/"
    publisher: "Cloud Security Alliance (CSA Labs)"
    date: "2026-07-10"
    role: primary
  - url: "https://github.com/advisories/GHSA-hp5m-24vp-vq2q"
    publisher: "GitHub Security Advisories"
    date: "2026-05"
    role: corroborating
  - url: "https://github.com/advisories/GHSA-4r4w-2wgp-w7cj"
    publisher: "GitHub Security Advisories"
    date: "2026-06"
    role: corroborating
closed_sources: []
evidence:
  - quote: "the client trusted server-sent events of type \"execute\" and evaluated their contents using JavaScript's new Function() constructor -- effectively treating output from an untrusted, attacker-controlled model server as executable code running inside the victim's authenticated browser session"
    publisher: "Cloud Security Alliance (CSA Labs)"
  - quote: "CVE-2025-63681 (the task-cancellation IDOR, CVSS 2.1), has no released patch as of this writing; upgrading to the latest version does not close this cluster's exposure completely."
    publisher: "Cloud Security Alliance (CSA Labs)"
verification: multi-source
sourcing_note: "CSA Labs synthesis is the primary; two of the cluster's advisories independently confirmed against the GitHub Security Advisory Database this run. NVD later reassessed CVE-2025-64496 to CVSS 8.0 (advisory base was 7.3, recorded here). CVE-2025-63681 has no fixed version as of publication."
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 1
watchlist_hit: false
actions:
  - "Confirm Open WebUI instances run ≥ 0.9.6; audit which accounts hold the workspace.tools permission and revoke it from any account not authoring executable functions — that permission is what converts client-side token theft into server-side RCE."
  - "Restrict the Direct Connections feature to fully-trusted model servers only, and place the Open WebUI admin interface and API behind an authenticating reverse proxy / SSO gateway / VPN rather than exposing it directly — CVE-2025-63681 has no patch, so a compensating control is the only mitigation for it."
migrated_from: null
---

CSA Labs' research note ties six broken-access-control CVEs disclosed in the self-hosted Open WebUI LLM front-end between November 2025 and June 2026 to a single architectural cause: authorization implemented ad hoc, endpoint by endpoint, rather than enforced through one policy layer that asks a consistent question — not "is this a valid session" but "is this specific user permitted to perform this specific action on this specific resource" ([CSA Labs, 2026-07-10](https://labs.cloudsecurityalliance.org/research/csa-research-note-open-webui-access-control-cves-20260710-cs/)). The most severe, CVE-2025-64496, exploits the Direct Connections feature: the client trusted server-sent events of type "execute" and evaluated them with JavaScript's `new Function()`, treating output from an attacker-controlled model server as code in the victim's authenticated browser session — enough to steal the auth token from browser local storage, and, for a session holding the `workspace.tools` permission, to escalate via the backend's unsandboxed Python `exec()` to full RCE on the host (fixed 0.6.35; NVD later scored it 8.0 versus the advisory's 7.3). Four more affect the 0.9.x line: CVE-2026-44556 (7.1) reaches any configured model through the `/api/openai/responses` proxy that checks only session validity, not per-model grants (CWE-862); CVE-2026-44557 (4.3) exposes system-wide knowledge-base metadata via an incomplete allowlist; CVE-2026-44564 (5.4) lets a read-only Socket.IO room member emit `ydoc:document:update` events because the handler checks room membership, not write permission; and CVE-2026-54015 (6.4) is a prompt-history IDOR validating the URL prompt-ID but not the caller-supplied history-ID (CWE-639). CVE-2025-63681 (2.1, task-cancellation IDOR) "remains unpatched as of this writing" ([CSA Labs, 2026-07-10](https://labs.cloudsecurityalliance.org/research/csa-research-note-open-webui-access-control-cves-20260710-cs/)); two of the advisories were confirmed against the GitHub Security Advisory Database this run ([GitHub Security Advisories](https://github.com/advisories/GHSA-hp5m-24vp-vq2q); [GitHub Security Advisories](https://github.com/advisories/GHSA-4r4w-2wgp-w7cj)).

Because Open WebUI is self-hosted rather than a managed service, the compensating-control burden falls on the operator, not a vendor — and self-hosting is exactly the deployment public-sector and research teams choose to keep prompts, documents and credentials off third-party SaaS, which is why the cluster matters to this constituency. **Defender takeaway:** the transferable lesson is the pattern, not any one CVE — a feature set that grew fast (proxy routing, retrieval, real-time collaboration, prompt versioning) each answered "is this action authorized" locally, and five of those answers were incomplete, so treat further same-class defects as plausible and gate the whole surface centrally. Concretely: log and alert on the OpenAI proxy router, task-management and Socket.IO collaboration endpoints for authenticated users reaching resources outside their expected scope, and give `workspace.tools` the scrutiny of an RCE-equivalent privilege.
