Security Advisory

CVE-2024-7046

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-20 10:09:38
Last updated 2025-10-15 12:50:37
Assigner @huntr_ai
State PUBLISHED

Description

An improper access control vulnerability in open-webui/open-webui v0.3.8 allows an attacker to view admin details. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the /api/v1/auths/admin/details interface to retrieve the first admin (owner) details.