CVE-2026-44561 | open-webui Open WebUI up to 0.8.x API is_user_channel_member is_active authorization (GHSA-hmgr-67hw-j2cq)
A vulnerability marked as critical has been reported in open-webui Open WebUI up to 0.8.x. The impacted element is the function is_user_channel_member of the component API. Performing a manipulation of the argument is_active results in incorrect authorization.
This vulnerability is known as CVE-2026-44561. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.