CVE-2026-44551: Open WebUI: LDAP Empty Password Authentication Bypass

Published May 8, 2026
·
Updated

LDAP Empty Password Authentication Bypass

Affected Component

LDAP authentication endpoint: - backend/openwebui/routers/auths.py (lines 468-477, user bind with empty password) - backend/openwebui/models/auths.py (lines 58-60, LdapForm model)

Affected Versions

Current main branch (commit 6fdd19bf1) and likely all versions with LDAP authentication support.

Description

The LDAP authentication endpoint does not validate that the submitted password is non-empty before performing a Simple Bind against the LDAP server. Per RFC 4513 Section 5.1.2, a Simple Bind with a valid DN and an empty password constitutes an "unauthenticated simple authentication" — many LDAP servers (including OpenLDAP in default configuration and some Active Directory setups) return success (resultCode 0) for this operation.

The LdapForm Pydantic model accepts password: str with no minimum length constraint, so an empty string passes validation. The subsequent Connection.bind() call succeeds on vulnerable LDAP servers, and the application issues a full session token for the target user.

python models/auths.py:58-60 — no minlength on password class LdapForm(BaseModel): user: str password: str

auths.py:469-477 — empty password reaches LDAP bind connectionuser = Connection( server, userdn, formdata.password, # can be "" autobind='NONE', authentication='SIMPLE', ) if not await asyncio.tothread(connectionuser.bind): raise HTTPException(400, 'Authentication failed.')

If bind succeeds (which it does with empty password on many servers), execution continues and a full session token is issued

CVSS 3.1 Breakdown

| Metric | Value | Rationale | |--------|-------|-----------| | Attack Vector | Network (N) | Exploited remotely via the LDAP login endpoint | | Attack Complexity | Low (L) | Single request with an empty password field | | Privileges Required | None (N) | No prior authentication needed | | User Interaction | None (N) | No victim interaction required | | Scope | Unchanged (U) | Impact within the application's authentication boundary | | Confidentiality | High (H) | Full access to victim's account data — chats, files, API keys, settings | | Integrity | High (H) | Can modify victim's data, settings, send messages as victim | | Availability | None (N) | No direct denial of service |

Attack Scenario

1. LDAP authentication is enabled on the Open WebUI instance. 2. The underlying LDAP server accepts unauthenticated simple binds (OpenLDAP default, some AD configs). 3. Attacker sends: POST /api/v1/auths/ldap {"user": "adminusername", "password": ""} 4. The app DN bind succeeds normally (line 366), finds the target user via LDAP search. 5. The user bind (line 469-477) sends a Simple Bind with the target's DN and an empty password. 6. The LDAP server returns success for the unauthenticated bind. 7. authenticateuserbyemail (line 507) issues a full session token for the target user. 8. Attacker has complete access to the victim's account.

Impact

- Complete authentication bypass — any LDAP user account can be taken over without knowing the password - Includes admin accounts if they authenticate via LDAP - No rate limiting on the LDAP endpoint (unlike the password signin endpoint) - Zero interaction required from the victim

Preconditions

- LDAP must be enabled (ENABLELDAP=True, disabled by default) - The LDAP server must accept unauthenticated simple binds with empty passwords (OpenLDAP default behavior, configurable on AD) - Attacker must know a valid LDAP username

Other sources

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is non-empty before performing a Simple Bind against the LDAP server. The LdapForm Pydantic model accepts password: str with no minimum length constraint, so an empty string passes validation. The subsequent Connection.bind() call succeeds on vulnerable LDAP servers, and the application issues a full session token for the target user. This vulnerability is fixed in 0.9.0.

MITRE

Affected Software

2 affected componentsFixes available
pip/open-webui<=0.8.12
0.9.0
openwebui Open WebUI<0.9.0

Event History

May 8, 2026
Advisory Published
via GitHub·07:38 PM
Data Sourced
via GitHub·07:38 PM
DescriptionSeverityWeaknessAffected Software
May 15, 2026
CVE Published
via MITRE·07:59 PM
Data Sourced
via MITRE·07:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-44551?

CVE-2026-44551 is classified as a high severity vulnerability due to its potential to allow unauthorized access through LDAP using empty passwords.

2

How do I fix CVE-2026-44551?

To fix CVE-2026-44551, update the open-webui package to version 0.9.0 or later.

3

What types of systems are affected by CVE-2026-44551?

CVE-2026-44551 affects systems that use open-webui versions up to 0.8.12 and utilize LDAP for authentication.

4

What does CVE-2026-44551 exploit?

CVE-2026-44551 exploits an authentication bypass vulnerability that allows LDAP user binding with an empty password.

5

How can I determine if my system is vulnerable to CVE-2026-44551?

You can determine if your system is vulnerable to CVE-2026-44551 by checking the version of the open-webui package being used and whether it is below version 0.9.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203