Open-WebUI Improper Access Control Vulnerability in Admin Chat Management

Vulnerability

A vulnerability allowing improper access control has been identified in Open-WebUI version 0.3.8. This issue arises on the frontend admin page, where administrators are supposed to see only the chats of non-admin members. However, by altering the user_id parameter, it is possible to access the chats of any administrator, including those of other admin (owner) accounts.

Impact

Exploitation of this vulnerability allows administrators to improperly access and view chats of other administrators, including owner accounts.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.2
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.