A vulnerability was found in open-webui WebUI up to 0.9.4 . It has been classified as problematic . Affected by this issue is the function insert_new_feedback of the file /api/v1/evaluations/feedback . Performing a manipulation of the argument server-derived results in dynamically-determined object attributes. This vulnerability is cataloged as CVE-2026-45396 . It is possible to initiate the attack remotely. There is no exploit available. Upgrading the affected component is recommended.