An authentication bypass vulnerability exists in Open...
High severity
Unreviewed
Published
Dec 18, 2025
to the GitHub Advisory Database
•
Updated Jan 22, 2026
Description
Published by the National Vulnerability Database
Dec 18, 2025
Published to the GitHub Advisory Database
Dec 18, 2025
Last updated
Jan 22, 2026
An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configuration data to unauthenticated remote attackers.
References