Skip to content

CVE-2026-54021

Incorrect Authorization: is CVE-2026-54021real, exploitable, or a false positive? Here's the community verdict.

Medium · CVSS 6.3CWE-863 · Incorrect Authorization

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, several direct, index-addressed Ollama proxy routes accept a caller-supplied url_idx path parameter and use it as a raw index into the admin-configured OLLAMA_BASE_URLS list. Access control on these routes validates only whether the user may use the requested model, never which backend the request is routed to. Any authenticated user can append an arbitrary url_idx to force their request onto an Ollama backend they were never authorized to reach, including internal, higher-privilege, or explicitly admin-disabled backends. This vulnerability is fixed in 0.9.6.

Published

Embed this verdict
TruePositive verdict for CVE-2026-54021
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2026-54021/badge.svg)](https://www.truepositive.app/cve/CVE-2026-54021)
HTML
<a href="https://www.truepositive.app/cve/CVE-2026-54021"><img src="https://www.truepositive.app/cve/CVE-2026-54021/badge.svg" alt="TruePositive verdict for CVE-2026-54021"></a>

Live badge that updates automatically as the community verdict changes.

Community ground truth

In your experience, is this finding real and exploitable?

0 verdicts
Not a real issue

No account needed. Anonymous verdicts post as an unverified signal. Log in to make yours verified and earn reputation.

Field notes & remediation

Verdicts are the quick signal. Notes are the evidence and fixes behind them.

No notes yet. Be the first to share what you saw, or a fix that worked.

    Add a field note or remediationoptional
    Note type

    What are you adding?

    Markdown supported · minimum 20 characters.

    Same weakness: CWE-863 · Incorrect Authorization.