# CVE-2026-45397: Open WebUI - Authentication Bypass

> Live exploitation tracking for CVE-2026-45397 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-45397

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 5.3
- **Public exploit available:** Yes
- **Affected products:** Open WebUI
- **Weaknesses:** CWE-306 (Missing Authentication for Critical Function)
- **Tags:** ai_mcp, web_application

## Description

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns live RAG pipeline configuration to any unauthenticated HTTP client. No Authorization header, cookie, or API key is required. Every adjacent endpoint on the same router (/embedding, /config) is correctly guarded by get_admin_user making this a targeted omission. This vulnerability is fixed in 0.9.5.

## CrowdSec analysis

[CVE-2026-45397](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-45397) is an authentication bypass vulnerability in Open WebUI prior to version 0.9.5, where the GET /api/v1/retrieval/ endpoint exposes live RAG pipeline configuration data to any unauthenticated HTTP client. This flaw allows attackers to access sensitive configuration information without any credentials, potentially aiding in further attacks or reconnaissance. The issue is resolved in version 0.9.5.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

Data from the CrowdSec community indicates that exploitation of CVE-2026-45397 is highly selective and intelligence-driven. Threat actors use advanced reconnaissance and carefully choose their targets, often as part of sophisticated campaigns or advanced persistent threat operations.
Telemetry from the CrowdSec network also shows that exploitation activity for CVE-2026-45397 remains steady week-over-week. Attack volumes are consistent with long-term trends, indicating sustained interest from threat actors. CVE-2026-45397 continues to be an active part of the threat landscape and will likely remain this way for the forseeable future.

Attackers exploit unauthenticated access to the `/api/v1/retrieval/` endpoint to retrieve sensitive RAG pipeline configuration data from vulnerable Open WebUI instances. This information disclosure does not require authentication and exposes internal configuration details to remote attackers.

## Timeline

- 2026-05-15: CVE Published. CVE-2026-45397 is published to NVD.
- 2026-06-24: Rule Released. CrowdSec releases a rule to detect CVE-2026-45397 exploitation attempts against the CrowdSec Network.
- 2026-06-25: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-45397 for the first time.

## References

- https://github.com/open-webui/open-webui/security/advisories/GHSA-65pg-qhhw-mxwg
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-45397.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-45397) follows observed exploitation activity for CVE-2026-45397. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
