Skip to content

Known CVE

Open WebUI < 0.9.5 - Information Disclosure

Open WebUI < 0.9.5 contains an information disclosure vulnerability caused by unauthenticated access to GET /api/v1/retrieval/ endpoint, letting remote attackers retrieve live RAG pipeline configuration without authorization, exploit requires no authentication.

CVE-2026-45397

Medium2026CVSS 5.3CWE-862

cve2026 · open-webui · exposure · misconfig

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website