A vulnerability labeled as problematic has been found in open-webui Open WebUI up to 0.8.x . The affected element is an unknown function of the file /api/v1/models/import . Such manipulation leads to missing authorization. This vulnerability is traded as CVE-2026-44562 . The attack may be launched remotely. There is no exploit available. The affected component should be upgraded.