Skip to main content

Broken Access Control in Open WebUI

An incomplete authorization check in Open WebUI allowed low privileged attackers to access sensitive tool data.
CVE-2026-34222

Read the full advisory here

Share this article

Dive deeper

  • Service Focus

Cybersecurity

  • Magazine

Digital security magazine 17

  • Magazine

Digital security magazine 18th Edition