CVE-2026-44566
Open WebUI could allow an internal attacker to write unauthorized files to the system
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
An internal attacker can manipulate file uploads in Open WebUI to save malicious files to restricted system locations. This could allow them to override critical settings or run unauthorized code, leading to a complete compromise of the platform.