A vulnerability identified as problematic has been detected in open-webui Open WebUI up to 0.8.x . Impacted is the function get_sources_from_items . This manipulation causes missing authorization. This vulnerability appears as CVE-2026-44560 . The attack may be initiated remotely. There is no available exploit. You should upgrade the affected component.