CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-45397Public Exploit

Open WebUI - Authentication Bypass (CVE-2026-45397)

PublishedMay 15, 2026
First SeenJun 25, 2026
Last Seen
Reported
CVSS5.3
ai_mcpweb_application

Description

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns live RAG pipeline configuration to any unauthenticated HTTP client. No Authorization header, cookie, or API key is required. Every adjacent endpoint on the same router (/embedding, /config) is correctly guarded by get_admin_user making this a targeted omission. This vulnerability is fixed in 0.9.5.

psychologyCrowdSec Analysis

CVE-2026-45397 is an authentication bypass vulnerability in Open WebUI prior to version 0.9.5, where the GET /api/v1/retrieval/ endpoint exposes live RAG pipeline configuration data to any unauthenticated HTTP client. This flaw allows attackers to access sensitive configuration information without any credentials, potentially aiding in further attacks or reconnaissance. The issue is resolved in version 0.9.5.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

Data from the CrowdSec community indicates that exploitation of CVE-2026-45397 is highly selective and intelligence-driven. Threat actors use advanced reconnaissance and carefully choose their targets, often as part of sophisticated campaigns or advanced persistent threat operations. Telemetry from the CrowdSec network also shows that exploitation activity for CVE-2026-45397 remains steady week-over-week. Attack volumes are consistent with long-term trends, indicating sustained interest from threat actors. CVE-2026-45397 continues to be an active part of the threat landscape and will likely remain this way for the forseeable future.

Attackers exploit unauthenticated access to the /api/v1/retrieval/ endpoint to retrieve sensitive RAG pipeline configuration data from vulnerable Open WebUI instances. This information disclosure does not require authentication and exposes internal configuration details to remote attackers.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-05-15
Rule Released2026-06-24
CrowdSec First Seen2026-06-25

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.