Back

MEDIUM

Open WebUI: Channel Access Grants Bypass filter_allowed_access_grants

Published May 15, 2026

Description

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the channel router does not call filter_allowed_access_grants on either create or update paths. A non-admin user who can create group channels (or who owns a channel) can submit arbitrary access grants — including public wildcard grants — and those grants are stored verbatim, bypassing the admin's permission framework. This vulnerability is fixed in 0.9.0.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 15, 2026
Updated May 19, 2026
Reserved May 6, 2026
CISA Vulnrichment
Updated May 19, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published May 15, 2026
Updated May 19, 2026
Exploited since n/a
EUVD-2026-30621 GHSA-7RJH-PX4V-5W55