CVE-2026-34222: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access control vulnerability in tool values. This issue...
Added to the CISA Known Exploited Vulnerabilities catalog on 01 Apr 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 7.7.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access control vulnerability in tool values. This issue has been patched in version 0.8.11.
Required action: Review and patch if applicable to your AI infrastructure.