CVE-2026-45349: Open WebUI has Broken Access Control for Completions API
(updated )
Any user X can continue the conversation of any other user Y, as long as the Chat ID of Y is known. User X does not even need to be an admin to do so.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-45349 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →