CVE-2026-44571 | open-webui Open WebUI up to 0.8.5 Message update authorization (GHSA-jgj3-r8hr-9pjw)
A vulnerability identified as problematic has been detected in open-webui Open WebUI up to 0.8.5. This affects an unknown part of the file /api/v1/channels/{channel_id}/messages/{message_id}/update of the component Message Handler. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2026-44571. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.