CVE-2026-44551: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is ...

Added to the CISA Known Exploited Vulnerabilities catalog on 15 May 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 9.1.

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is non-empty before performing a Simple Bind against the LDAP server. The LdapForm Pydantic model accep...

Required action: Review and patch if applicable to your AI infrastructure.