A vulnerability described as critical has been identified in open-webui Open WebUI up to 0.8.x . This affects an unknown function of the file /api/generate . Executing a manipulation can lead to missing authorization. This vulnerability is handled as CVE-2026-44563 . The attack can be executed remotely. There is not any exploit available. Upgrading the affected component is recommended.