
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34222 is a broken access control vulnerability in Open WebUI's Tool Valves endpoint that allows any authenticated low-privileged user to read sensitive valve configuration data, including API keys stored for third-party service integrations. It affects Open WebUI versions prior to 0.8.11 and was published on March 31, 2026, by researcher "timoles" coordinated through sec-consult. The vulnerability carries a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory, Github Advisory).
The root cause is CWE-285 (Improper Authorization): the Tool Valves route handler in backend/open_webui/routers/tools.py (lines 513–531) uses only get_verified_user as its dependency, which confirms the user is authenticated but does not verify administrative privileges before returning valve data. Because Open WebUI Tool IDs are derived deterministically from tool names (making them trivially guessable), any authenticated "Member" user can craft a simple HTTP GET request to /api/v1/tools/id/<tool_id>/valves with their own bearer token to retrieve all valve configuration, including admin-configured API keys. No special tooling or elevated access is required beyond a valid session token (GitHub Advisory, Github Advisory).
Successful exploitation results in full disclosure of all data stored in Tool Valves, which may include API keys and credentials for third-party backend systems such as internal knowledge bases, email servers, or e-commerce backends. A low-privileged "Member" user can leverage these credentials to access and interact with those third-party systems under the context of the configured Open WebUI technical user, potentially enabling lateral movement into integrated services. There is no integrity or availability impact — the vulnerability is purely a confidentiality issue, but the scope change (S:C) reflects that exploitation extends beyond the Open WebUI instance itself (GitHub Advisory).
A detailed proof-of-concept (PoC) with step-by-step reproduction instructions is publicly available on SecLists Full Disclosure (SecLists PoC). The exploit requires only a valid "Member"-level account and knowledge of a tool ID, which is trivially guessable from tool names. The EPSS score is approximately 0.016% (4th percentile), indicating low predicted exploitation probability in the near term. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (Github Advisory).
GET /api/v1/tools/id/<tool_id>/valves HTTP/1.1
Host: <target_host>
Authorization: Bearer <member_jwt_token>/api/v1/tools/id/*/valves originating from non-admin user accounts; repeated enumeration of multiple tool IDs from the same source IP.GET /api/v1/tools/id/<tool_id>/valves requests authenticated with low-privileged user tokens (especially from accounts that do not normally interact with tool administration endpoints); HTTP 200 responses to these requests from non-admin users.Upgrade Open WebUI to version 0.8.11 or later, which patches the Tool Valves access control by properly verifying user permissions before returning valve configuration data. The v0.8.11 release notes confirm: "Tool configuration endpoints now properly verify user permissions, preventing unauthorized access to tool settings" and "Tool valves access control: The tool user valves endpoints now properly verify ownership and access grants before returning or updating configuration." No official workaround is available for unpatched versions; until upgrade is possible, consider restricting Open WebUI access to trusted users only and rotating any API keys stored in Tool Valves (Open WebUI v0.8.11, GitHub Advisory).
The vulnerability was discovered by researcher "timoles" and coordinated through sec-consult, who published the advisory and PoC via SecLists Full Disclosure (SecLists PoC). A Bluesky post from cyberhub.blog referenced the CVE shortly after disclosure. Check Point also published a defense advisory (CPAI-2026-4244) covering this vulnerability (Check Point Advisory). Community reaction has been moderate, consistent with a medium-severity information disclosure issue in a self-hosted AI platform.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."