Open WebUI: 150+ advisories in 2026, and an admin login means Python on your server
Risk / Filed 28 Sep 2026 / CVE-2025-64496, CVE-2025-46719, CVE-2026-59214, CVE-2026-45395, CVE-2026-44551
open-webuiollamadockerexposed-api
What: Open WebUI has published 165 GitHub security advisories: 1 in 2024, 6 in 2025 and
158 so far in 2026. Most are stored XSS, session-token theft, SSRF and access-control bugs. They
all end the same way: steal an admin's session, then use Functions or Tools to run Python on the
server. That's by design, not a bug. Admin, or workspace.tools permission, equals code
execution on the host. The newest batch (fixed in 0.11.4, advisories out Sep 27-28) includes
GHSA-vpq8-f445-hcq7. In 0.7.0 to 0.11.3, any website you visit while logged in can steal your
session token, with community sharing on (the default). In June 2025 Sysdig caught an attacker
on an internet-facing Open WebUI with auth turned off. The attacker uploaded a malicious Tool and
dropped XMRig, T-Rex, process hiders and a Windows infostealer. Sysdig counted over 17,000
instances on Shodan at the time.
Who it hits: You're affected if any of these is true:
-
WEBUI_AUTH=False. Every visitor is signed in as theadmin@localhostadmin. With the port reachable, anyone can run Python on your box. This is the setup Sysdig saw exploited. -
A fresh install exposed before you create your account. The first signup becomes admin, whoever does it. Signup turns itself off after that.
-
Signup turned back on with
DEFAULT_USER_ROLE=user. Strangers get working accounts, and most of the 2026 bugs only need a normal user account. -
Older versions, even behind a login. Examples:
- CVE-2025-64496 (≤ 0.6.34): Direct Connections, malicious model server runs JS, token theft.
- CVE-2025-46719 (0.6.5): stored XSS in chat, admin token, RCE via Functions.
- CVE-2026-45395 (< 0.9.5): a user with write access to one tool gets code execution.
- CVE-2026-59214 (< 0.10.0): Pyodide in a shared chat, RCE when an admin clicks Run.
-
CVE-2026-44551 (≤ 0.8.12): LDAP with an empty password logs in as anyone, on OpenLDAP defaults.
-
Ollama published next to it on 0.0.0.0:11434. Even if the UI is locked down, the raw API is open. See the exposed-inference-APIs card.
Check if you're affected:
# Version + auth state, no login needed. Want: version >= 0.11.4, auth true,
# enable_signup false, and no "onboarding": true (that means nobody has claimed admin yet).
curl -s http://localhost:3000/api/config | jq '{version, onboarding, auth: .features.auth, enable_signup: .features.enable_signup, ldap: .features.enable_ldap}'
# Same check from OUTSIDE your network (phone hotspot, VPS) against your public hostname/IP.
# Any JSON back means the UI is reachable from the internet.
# Env set on the container (UI changes override these after first boot, so trust /api/config):
docker inspect open-webui --format '{{.Config.Image}}{{range .Config.Env}}{{"\n"}}{{.}}{{end}}' | grep -E 'open-webui:|WEBUI_AUTH|ENABLE_SIGNUP|DEFAULT_USER_ROLE|ENABLE_DIRECT_CONNECTIONS'
# Is Ollama exposed next to it? Want 127.0.0.1 only.
ss -ltnp | grep -E ':(11434|3000|8080)\b'
Do this:
-
Tonight: upgrade to 0.11.4 or newer. Pin the tag instead of
:mainso you know what you're running:docker pull ghcr.io/open-webui/open-webui:v0.11.4, then recreate the container with the same volume (-v open-webui:/app/backend/data). pip installs:pip install -U open-webui. -
If
features.authisfalse, turn auth back on: removeWEBUI_AUTH=Falseand set a password on the admin account. If it's reachable from outside, take it offline first. Never run no-auth Open WebUI on anything but127.0.0.1. -
Claim the admin account before exposing a new install. Better: set
WEBUI_ADMIN_EMAILandWEBUI_ADMIN_PASSWORDon first boot, which creates the admin and turns signup off. -
Admin Panel > Settings > General: signup off unless you need it, and Default User Role
pending. Only give Tools/Functions access to people you'd trust with a shell on the host. If you don't use plugins, setENABLE_PLUGINS=false. Also turn off Direct Connections, community sharing, and code execution/interpreter unless you use them. -
Don't port-forward 3000/8080. Reach it over Tailscale or WireGuard, or put it behind Cloudflare Access or another forward-auth layer. Publish Ollama as
127.0.0.1:11434:11434. -
Confirm: re-run the
curl. It should show the new version,auth: true, andenable_signup: false. From outside it should time out or hit your auth proxy first.
If you were already hit: In Workspace > Tools and Admin > Functions, look for anything you
didn't install. Check Admin > Users for unknown admins. Inside the container, look for
cryptominers (docker exec open-webui ps aux). Rotate WEBUI_SECRET_KEY (this logs out every
session) and every provider API key stored in Connections. Assume the host is compromised if
an unknown Tool or Function ran, and rebuild it.
Why this level: Four yeses: often exposed through tunnels and port-forwards, exploited in the wild (Sysdig) with public PoCs in the advisories, a core lab AI tool, and admin access means Python on the host. No-friction is "no" because a default install creates the first admin, turns signup off, and sets new users to pending. Most current bugs need an account or a click. The patch is 7 days old, so no auto-update downgrade.
Sources
- Open WebUI GitHub security advisories (full list)
- Open WebUI v0.11.4 release notes (security and access-control fixes)
- GHSA-vpq8-f445-hcq7: any website can steal a signed-in user's session token (0.7.0 to 0.11.3, fixed 0.11.4)
- CVE-2025-64496: Direct Connections SSE code injection, token theft to RCE (fixed 0.6.35)
- Infosecurity Magazine: CVE-2025-64496 (Cato CTRL research)
- CVE-2025-46719: stored XSS in chat markdown, admin token theft to RCE via Functions (fixed 0.6.6)
- CVE-2026-59214: Pyodide in a shared chat to server-side RCE (fixed 0.10.0)
- CVE-2026-45395: tool update endpoint missing permission check, code execution (fixed 0.9.5)
- CVE-2026-44551: LDAP empty-password auth bypass, CVSS 9.1 (fixed 0.9.0)
- Sysdig (June 2025): no-auth Open WebUI hit via Tools, cryptominers and infostealers deployed
- Wiz threat entry: Open WebUI misconfiguration exploited for cryptojacking
- Open WebUI docs: hardening guide
- Open WebUI docs: env vars (ENABLE_SIGNUP, DEFAULT_USER_ROLE, PersistentConfig)
How severity is decided. Source file: risks/2026-09-28-open-webui-security.md.