CVE-2026-34222: Open WebUI has Broken Access Control in Tool Valves
(updated )
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access control vulnerability in tool values. This issue has been patched in version 0.8.11
References
Code Behaviors & Features
Detect and mitigate CVE-2026-34222 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →