The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,140 vulnerabilities with CWE-862
CVE-2026-45242
HIGH
Summarize < 0.15.1 Path Traversal via slidesDir Parameter
CVSS 7.1
CVE-2026-5163
MEDIUM
Missing authorization check in AI message rewrite endpoint allows access to private thread content
CVSS 6.5
CVE-2026-3117
MEDIUM
Instance and webhook GitLab plugin commands were able to be run by non-admin users
CVSS 6.5
CVE-2026-3637
MEDIUM
Mattermost fails to enforce create_post permission when editing posts
CVSS 4.3
CVE-2026-1631
MEDIUM
Feeds for YouTube < 2.6.4 - Subscriber+ License Data Deletion
CVSS 5.4
CVE-2026-8681
MEDIUM
Essential Chat Support <= 1.0.1 - Missing Authorization to Unauthenticated Settings Reset via 'ecs_reset_settings' Parameter
CVSS 5.3
CVE-2026-45667
MEDIUM
Open WebUI Memories Endpoint - Unauthenticated Embedding Generation DoS
CVSS 6.5
CVE-2026-45350
HIGH
Open WebUI: Chat completion API allows tool restrictions to be bypassed
CVSS 7.1
CVE-2026-44571
MEDIUM
Open WebUI: Improper Authorization in Standard Channels Allows Message Updates with Read Permission
CVSS 6.5
CVE-2026-44569
HIGH
Open WebUI: Insecure Message Access Breaks Authorization
CVSS 7.1
CVE-2026-45395
HIGH
Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
CVSS 7.2
CVE-2026-45399
HIGH
Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
CVSS 7.1
CVE-2026-44563
MEDIUM
Open WebUI: Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show
CVSS 5.4
CVE-2026-44562
MEDIUM
Open WebUI: Model Import Overwrites Any Model Without Ownership Check
CVSS 6.5
CVE-2026-44560
MEDIUM
Open WebUI: Unauthorized File and Knowledge Base Content Access via RAG Vector Search
CVSS 6.5
CVE-2026-44559
MEDIUM
Open WebUI: Missing Access Check on Channel Members Endpoint for Standard Channels
CVSS 4.3
CVE-2026-44558
MEDIUM
Open WebUI: Channel Access Grants Bypass filter_allowed_access_grants
CVSS 5.4
CVE-2026-44556
HIGH
Open WebUI: responses passthrough endpoint lacks access control authorization
CVSS 7.1
CVE-2026-44555
HIGH
Open WebUI: Base Model Routing Bypasses Access Control via Model Chaining
CVSS 7.6
CVE-2026-44554
HIGH
Open WebUI: Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
CVSS 8.1
CVE-2026-44550
MEDIUM
Open WebUI: Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
CVSS 5.0
CVE-2026-46365
MEDIUM
phpMyFAQ - Missing Authorization in Tag Deletion Endpoint
CVSS 5.4
CVE-2026-45007
MEDIUM
phpMyFAQ - Missing Permission Check on 12 Configuration API Endpoints Allows Information Disclosure
CVSS 4.3
CVE-2026-44719
MEDIUM
Mathesar: Missing collaborator checks allowed access to database-scoped Mathesar metadata
CVE-2026-44718
MEDIUM
Mathesar: Missing collaborator checks allowed access to saved explorations in other databases
Details
Vulnerabilities
8,140
Exploit Likelihood
High