CVE-2026-44556: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the OpenAI router accepts any authenticated user and fo...

Added to the CISA Known Exploited Vulnerabilities catalog on 15 May 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.1.

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the OpenAI router accepts any authenticated user and forwards requests directly to upstream LLM providers without enforcing per-model access control. While...

Required action: Review and patch if applicable to your AI infrastructure.