What the vulnerability does

01Description

An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configuration data to unauthenticated remote attackers.

Key dates

02Disclosure timeline

December 18, 2025 CVE published
January 22, 2026 Record updated