Missing Authorization Affecting open-webui package, versions [,0.9.6)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-OPENWEBUI-17400337
  • published22 Jun 2026
  • disclosed17 Jun 2026
  • creditHwwg

Introduced: 17 Jun 2026

CVE-2026-54016  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade open-webui to version 0.9.6 or higher.

Overview

open-webui is an Open WebUI

Affected versions of this package are vulnerable to Missing Authorization in the search_knowledge_files function when native function calling is enabled and the selected model has no attached knowledge bases. An attacker can retrieve metadata for files from private or restricted knowledge bases by supplying an arbitrary knowledge_id without proper authorization checks. This is only exploitable if the attacker is authenticated, knows the target knowledge_id, the selected model has no attached knowledge bases, builtin tools are enabled, the knowledge builtin tool category is enabled, and native function calling is enabled.

CVSS Base Scores

version 4.0
version 3.1