CVE-2026-44553: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, administrative role changes and user deletions do not iterate SESSION_POOL to disc...
Added to the CISA Known Exploited Vulnerabilities catalog on 15 May 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 8.1.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, administrative role changes and user deletions do not iterate SESSION_POOL to disconnect affected sessions. As a result, a user whose admin role has been revoked retains admin privil...
Required action: Review and patch if applicable to your AI infrastructure.