ACT TONIGHT

Open WebUI: 150+ advisories in 2026, and an admin login means Python on your server

Risk / Filed 28 Sep 2026 / CVE-2025-64496, CVE-2025-46719, CVE-2026-59214, CVE-2026-45395, CVE-2026-44551

open-webuiollamadockerexposed-api

What: Open WebUI has published 165 GitHub security advisories: 1 in 2024, 6 in 2025 and 158 so far in 2026. Most are stored XSS, session-token theft, SSRF and access-control bugs. They all end the same way: steal an admin's session, then use Functions or Tools to run Python on the server. That's by design, not a bug. Admin, or workspace.tools permission, equals code execution on the host. The newest batch (fixed in 0.11.4, advisories out Sep 27-28) includes GHSA-vpq8-f445-hcq7. In 0.7.0 to 0.11.3, any website you visit while logged in can steal your session token, with community sharing on (the default). In June 2025 Sysdig caught an attacker on an internet-facing Open WebUI with auth turned off. The attacker uploaded a malicious Tool and dropped XMRig, T-Rex, process hiders and a Windows infostealer. Sysdig counted over 17,000 instances on Shodan at the time.

Who it hits: You're affected if any of these is true:

  • WEBUI_AUTH=False. Every visitor is signed in as the admin@localhost admin. With the port reachable, anyone can run Python on your box. This is the setup Sysdig saw exploited.

  • A fresh install exposed before you create your account. The first signup becomes admin, whoever does it. Signup turns itself off after that.

  • Signup turned back on with DEFAULT_USER_ROLE=user. Strangers get working accounts, and most of the 2026 bugs only need a normal user account.

  • Older versions, even behind a login. Examples:

  • CVE-2025-64496 (≤ 0.6.34): Direct Connections, malicious model server runs JS, token theft.
  • CVE-2025-46719 (0.6.5): stored XSS in chat, admin token, RCE via Functions.
  • CVE-2026-45395 (< 0.9.5): a user with write access to one tool gets code execution.
  • CVE-2026-59214 (< 0.10.0): Pyodide in a shared chat, RCE when an admin clicks Run.
  • CVE-2026-44551 (≤ 0.8.12): LDAP with an empty password logs in as anyone, on OpenLDAP defaults.

  • Ollama published next to it on 0.0.0.0:11434. Even if the UI is locked down, the raw API is open. See the exposed-inference-APIs card.

Check if you're affected:

# Version + auth state, no login needed. Want: version >= 0.11.4, auth true,
# enable_signup false, and no "onboarding": true (that means nobody has claimed admin yet).
curl -s http://localhost:3000/api/config | jq '{version, onboarding, auth: .features.auth, enable_signup: .features.enable_signup, ldap: .features.enable_ldap}'
# Same check from OUTSIDE your network (phone hotspot, VPS) against your public hostname/IP.
# Any JSON back means the UI is reachable from the internet.
# Env set on the container (UI changes override these after first boot, so trust /api/config):
docker inspect open-webui --format '{{.Config.Image}}{{range .Config.Env}}{{"\n"}}{{.}}{{end}}' | grep -E 'open-webui:|WEBUI_AUTH|ENABLE_SIGNUP|DEFAULT_USER_ROLE|ENABLE_DIRECT_CONNECTIONS'
# Is Ollama exposed next to it? Want 127.0.0.1 only.
ss -ltnp | grep -E ':(11434|3000|8080)\b'

Do this:

  1. Tonight: upgrade to 0.11.4 or newer. Pin the tag instead of :main so you know what you're running: docker pull ghcr.io/open-webui/open-webui:v0.11.4, then recreate the container with the same volume (-v open-webui:/app/backend/data). pip installs: pip install -U open-webui.

  2. If features.auth is false, turn auth back on: remove WEBUI_AUTH=False and set a password on the admin account. If it's reachable from outside, take it offline first. Never run no-auth Open WebUI on anything but 127.0.0.1.

  3. Claim the admin account before exposing a new install. Better: set WEBUI_ADMIN_EMAIL and WEBUI_ADMIN_PASSWORD on first boot, which creates the admin and turns signup off.

  4. Admin Panel > Settings > General: signup off unless you need it, and Default User Role pending. Only give Tools/Functions access to people you'd trust with a shell on the host. If you don't use plugins, set ENABLE_PLUGINS=false. Also turn off Direct Connections, community sharing, and code execution/interpreter unless you use them.

  5. Don't port-forward 3000/8080. Reach it over Tailscale or WireGuard, or put it behind Cloudflare Access or another forward-auth layer. Publish Ollama as 127.0.0.1:11434:11434.

  6. Confirm: re-run the curl. It should show the new version, auth: true, and enable_signup: false. From outside it should time out or hit your auth proxy first.

If you were already hit: In Workspace > Tools and Admin > Functions, look for anything you didn't install. Check Admin > Users for unknown admins. Inside the container, look for cryptominers (docker exec open-webui ps aux). Rotate WEBUI_SECRET_KEY (this logs out every session) and every provider API key stored in Connections. Assume the host is compromised if an unknown Tool or Function ran, and rebuild it.

Why this level: Four yeses: often exposed through tunnels and port-forwards, exploited in the wild (Sysdig) with public PoCs in the advisories, a core lab AI tool, and admin access means Python on the host. No-friction is "no" because a default install creates the first admin, turns signup off, and sets new users to pending. Most current bugs need an account or a click. The patch is 7 days old, so no auto-update downgrade.

Sources

How severity is decided. Source file: risks/2026-09-28-open-webui-security.md.