CVE-2026-45345: Open WebUI missing authorization check at the model update function - models from other users can be updated
(updated )
A user can modify another user’s model even if its visibility is set to Private.
The finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on Open WebUI 0.5.4.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-45345 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →