Количество 3
Количество 3
CVE-2026-44551
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is non-empty before performing a Simple Bind against the LDAP server. The LdapForm Pydantic model accepts password: str with no minimum length constraint, so an empty string passes validation. The subsequent Connection.bind() call succeeds on vulnerable LDAP servers, and the application issues a full session token for the target user. This vulnerability is fixed in 0.9.0.
GHSA-2r4p-jpmg-48f4
Open WebUI has an LDAP Empty Password Authentication Bypass
BDU:2026-07029
Уязвимость функции Connection.bind() веб-интерфейса на базе искуственного интеллекта Open WebUI (ранее Ollama WebUI), позволяющая нарушителю обойти существующие механизмы безопасности
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-44551 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is non-empty before performing a Simple Bind against the LDAP server. The LdapForm Pydantic model accepts password: str with no minimum length constraint, so an empty string passes validation. The subsequent Connection.bind() call succeeds on vulnerable LDAP servers, and the application issues a full session token for the target user. This vulnerability is fixed in 0.9.0. | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
GHSA-2r4p-jpmg-48f4 Open WebUI has an LDAP Empty Password Authentication Bypass | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
BDU:2026-07029 Уязвимость функции Connection.bind() веб-интерфейса на базе искуственного интеллекта Open WebUI (ранее Ollama WebUI), позволяющая нарушителю обойти существующие механизмы безопасности | CVSS3: 9.1 | 1% Низкий | 3 месяца назад |
Уязвимостей на страницу