S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jun 3, 2026

CVE-2026-45397 Scanner

CVE-2026-45397 Scanner - Information Disclosure vulnerability in Open WebUI

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-45397
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns live RAG pipeline configuration to any unauthenticated HTTP client. No Authorization header, cookie, or API key is required. Every adjacent endpoint on the same router (/embedding, /config) is correctly guarded by get_admin_user making this a targeted omission. This vulnerability is fixed in 0.9.5.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
open-webuiby open-webui
< 0.9.5
Updated Aug 19, 2026View on NVD →
Detail

Open WebUI is a widely used web interface platform that allows management and configuration of various web services. It is primarily utilized by web developers and system administrators in environments requiring robust web-based administration tools. The platform facilitates tasks like monitoring, configuring, and deploying web applications, offering real-time insights into system operations. Its user-friendly interface is designed to enhance efficiency and streamline workflows, providing an essential service for managing complex web environments. However, like any software, it requires diligent security practices to protect against vulnerabilities.

The vulnerability detected in Open WebUI involves unauthorized access to sensitive information due to inadequate restriction mechanisms. This allows remote attackers to retrieve live configuration data without the need for authentication. Information disclosure vulnerabilities such as this can serve as stepping stones for further exploitation, potentially compromising system integrity. The vulnerability specifically stems from the lack of access control on a particular API endpoint. Recognizing and addressing such vulnerabilities is crucial for maintaining system security and preventing unauthorized data exposure.

Technical details regarding this vulnerability indicate that it affects the GET /api/v1/retrieval/ endpoint. Exploitable without authentication, it allows retrieval of sensitive configuration parameters such as "CHUNK_SIZE" and "RAG_EMBEDDING_MODEL," which are components of the RAG pipeline configuration. The exposed information could facilitate attackers in understanding the system's configuration and identifying potential weaknesses for further exploitation. The endpoint returns the content with a status code of 200 and a content-type of application/json, indicative of a successful response containing sensitive data.

Exploitation of this vulnerability could have several adverse effects, including unauthorized access to confidential configuration settings. This could lead to system misconfigurations being exploited, data leaks, and potentially serve as a vector for launching additional attacks. Malicious actors could gain insights into the system's workings, thereby increasing the risk of targeted attacks or compromising the reliability of the service. Ensuring robust security measures and timely updates can mitigate these risks and safeguard sensitive information from being disclosed.

REFERENCES

Solution Advice
  • Ensure systems are updated to Open WebUI version 0.9.5 or later to address this issue.
  • Implement access controls on critical API endpoints to prevent unauthorized access.
  • Regularly audit system configurations and permissions to adhere to the principle of least privilege.
  • Monitor access logs for unauthorized access attempts and respond promptly to suspicious activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.