Open WebUIGHSA-gv26-qw3h-8qvp
Open WebUI Allows Viewing of Admin Details
Medium4.3CVE-2024-7046 · Published Mar 20, 2025 · updated Jul 7, 2026
An improper access control vulnerability in open-webui/open-webui v0.3.8 allows an attacker to view admin details. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the /api/v1/auths/admin/details interface to retrieve the first admin (owner) details.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| open-webui PyPI | <= 0.3.8 | No fix yet |
Details and references
More Open WebUI advisories
All Open WebUI| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability | High7.5 | No fix yet |
| Mar 202025 | Open WebUI denial of service through endpoint for converting markdown | High7.5 | No fix yet |
| Mar 202025 | Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint | High7.5 | No fix yet |
| Mar 202025 | Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions | High8.1 | 0.5.17 |
| Mar 202025 | Open WebUI stored cross-site scripting (XSS) vulnerability | High8.4 | No fix yet |
| Mar 202025 | Open WebUI Vulnerable to a Session Fixation Attack | High7.6 | No fix yet |