CVE-2026-45397 | open-webui Open WebUI up to 0.9.4 /api/v1/retrieval/ get_admin_user missing authentication (GHSA-65pg-qhhw-mxwg)
A vulnerability was found in open-webui Open WebUI up to 0.9.4. It has been declared as critical. This affects the function get_admin_user of the file /api/v1/retrieval/. Executing a manipulation can lead to missing authentication.
This vulnerability is registered as CVE-2026-45397. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.