CVE-2026-45396
Last modified
CVE-2026-45396 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the POST /api/v1/evaluations/feedback endpoint in Open WebUI v0.9.2 is vulnerable to mass assignment via FeedbackForm, which uses model_config = ConfigDict(extra='allow'). EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the POST /api/v1/evaluations/feedback endpoint in Open WebUI v0.9.2 is vulnerable to mass assignment via FeedbackForm, which uses model_config = ConfigDict(extra='allow'). Due to an insecure dictionary merge order in insert_new_feedback(), an authenticated attacker can inject a user_id field in the request body that overwrites the server-derived value, creating feedback records attributed to any arbitrary user. This corrupts the model evaluation leaderboard (Elo ratings) and enables identity spoofing. This vulnerability is fixed in 0.9.5.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openwebui | Open Webui | < 0.9.5 |
References
- https://github.com/open-webui/open-webui/security/advisories/GHSA-rjmp-vjf2-qf4gExploit, Vendor Advisory
- https://github.com/open-webui/open-webui/security/advisories/GHSA-rjmp-vjf2-qf4gExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-45396?
How severe is CVE-2026-45396?
How do I fix CVE-2026-45396?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4539A security flaw has been discovered in pygments up to 2.19.2…3.3
- CVE-2026-45390In OCaml-tar before 3.4.0, a crafted archive with ../ path s…9.1
- CVE-2026-45391A command injection vulnerability in Cribl Edge for Linux ve…8.5
- CVE-2026-45392DOM-based cross-site scripting (XSS) in Cribl Stream before …8.7
- CVE-2026-45393A vulnerability chain in Cribl Edge for Windows before 4.17.…8.5
- CVE-2026-45395Open WebUI is a self-hosted artificial intelligence platform…7.2
- CVE-2026-45397Open WebUI is a self-hosted artificial intelligence platform…5.3
- CVE-2026-45398Open WebUI is a self-hosted artificial intelligence platform…7.5
- CVE-2026-45399Open WebUI is a self-hosted artificial intelligence platform…7.1
- CVE-2026-4540A vulnerability was detected in projectworlds Online Notes S…7.3
- CVE-2026-45400Open WebUI is a self-hosted artificial intelligence platform…8.5
- CVE-2026-45401Open WebUI is a self-hosted artificial intelligence platform…8.5
Are you affected by CVE-2026-45396?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
