CVE-2026-56400: Openwebui Open Webui

Critical severity, CVSS 9.6. EPSS: 0.5% chance of exploitation in the next 30 days.

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them.

Affected products

  • Openwebui Open Webui: before 0.3.14 (fixed in 0.3.14)

Published 2026-07-15. Last modified 2026-07-16.