CVE-2026-34222: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-34222 is a broken access control vulnerability in Open WebUI's Tool Valves endpoint that allows any authenticated low-privileged user to read sensitive valve configuration data, including API keys stored for third-party service integrations. It affects Open WebUI versions prior to 0.8.11 and was published on March 31, 2026, by researcher "timoles" coordinated through sec-consult. The vulnerability carries a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory, Github Advisory).

Technical details

The root cause is CWE-285 (Improper Authorization): the Tool Valves route handler in backend/open_webui/routers/tools.py (lines 513–531) uses only get_verified_user as its dependency, which confirms the user is authenticated but does not verify administrative privileges before returning valve data. Because Open WebUI Tool IDs are derived deterministically from tool names (making them trivially guessable), any authenticated "Member" user can craft a simple HTTP GET request to /api/v1/tools/id/<tool_id>/valves with their own bearer token to retrieve all valve configuration, including admin-configured API keys. No special tooling or elevated access is required beyond a valid session token (GitHub Advisory, Github Advisory).

Impact

Successful exploitation results in full disclosure of all data stored in Tool Valves, which may include API keys and credentials for third-party backend systems such as internal knowledge bases, email servers, or e-commerce backends. A low-privileged "Member" user can leverage these credentials to access and interact with those third-party systems under the context of the configured Open WebUI technical user, potentially enabling lateral movement into integrated services. There is no integrity or availability impact — the vulnerability is purely a confidentiality issue, but the scope change (S:C) reflects that exploitation extends beyond the Open WebUI instance itself (GitHub Advisory).

Exploitability

A detailed proof-of-concept (PoC) with step-by-step reproduction instructions is publicly available on SecLists Full Disclosure (SecLists PoC). The exploit requires only a valid "Member"-level account and knowledge of a tool ID, which is trivially guessable from tool names. The EPSS score is approximately 0.016% (4th percentile), indicating low predicted exploitation probability in the near term. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify an Open WebUI instance running a version prior to 0.8.11. Enumerate or guess tool IDs — since tool IDs are derived from tool names (e.g., a tool named "email_fetcher" would have a predictable ID), this step requires minimal effort.
  2. Obtain a valid session token: Register or log in as any "Member"-level user on the target Open WebUI instance and capture the JWT bearer token from the browser's local storage or network traffic.
  3. Query the vulnerable endpoint: Send a GET request to the Tool Valves endpoint using the captured token:
GET /api/v1/tools/id/<tool_id>/valves HTTP/1.1
Host: <target_host>
Authorization: Bearer <member_jwt_token>
  1. Extract sensitive data: The server returns the full valve configuration in JSON, including any API keys or credentials configured by the administrator for third-party service integrations.
  2. Leverage extracted credentials: Use the obtained API keys to authenticate against the integrated third-party systems (e.g., internal APIs, email servers) under the context of the Open WebUI technical user (GitHub Advisory, SecLists PoC).

Indicators of compromise

  • Network: Unexpected GET requests to /api/v1/tools/id/*/valves originating from non-admin user accounts; repeated enumeration of multiple tool IDs from the same source IP.
  • Logs: Open WebUI access logs showing GET /api/v1/tools/id/<tool_id>/valves requests authenticated with low-privileged user tokens (especially from accounts that do not normally interact with tool administration endpoints); HTTP 200 responses to these requests from non-admin users.
  • Behavioral: A single user account querying multiple tool valve endpoints in rapid succession, suggesting automated enumeration of tool IDs.

Mitigation and workarounds

Upgrade Open WebUI to version 0.8.11 or later, which patches the Tool Valves access control by properly verifying user permissions before returning valve configuration data. The v0.8.11 release notes confirm: "Tool configuration endpoints now properly verify user permissions, preventing unauthorized access to tool settings" and "Tool valves access control: The tool user valves endpoints now properly verify ownership and access grants before returning or updating configuration." No official workaround is available for unpatched versions; until upgrade is possible, consider restricting Open WebUI access to trusted users only and rotating any API keys stored in Tool Valves (Open WebUI v0.8.11, GitHub Advisory).

Community reactions

The vulnerability was discovered by researcher "timoles" and coordinated through sec-consult, who published the advisory and PoC via SecLists Full Disclosure (SecLists PoC). A Bluesky post from cyberhub.blog referenced the CVE shortly after disclosure. Check Point also published a defense advisory (CPAI-2026-4244) covering this vulnerability (Check Point Advisory). Community reaction has been moderate, consistent with a medium-severity information disclosure issue in a self-hosted AI platform.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management