Open WebUI disclosed and patched a high-severity broken access control vulnerability in its Tool Valves feature, tracked as CVE-2026-34222 and GHSA-7429-hxcv-268m. The flaw affects versions earlier than v0.8.11 and allowed a low-privileged Member user with a valid authorization token to access sensitive valve configuration data that should have been restricted. According to the disclosure, the vulnerable endpoint did not properly enforce authorization checks, exposing secrets such as API keys used by backend integrations.
SEC Consult reported that exploitation required knowledge of a Tool ID, but said those identifiers were easy to derive because they are based on tool names and imported tools use predictable values. The issue was validated against Open WebUI v0.7.2, and the project confirmed a fix in v0.8.11, with remediation verified on the development branch before coordinated disclosure. Organizations running affected releases should treat Tool Valve secrets as potentially exposed and upgrade to a patched version.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
SEC Consult publicly disclosed a high-severity broken access control issue in Open WebUI on April 1, 2026, after confirming the fix on the development branch. The advisory said a Member-level user with a valid token could retrieve Tool Valve secrets if they knew or could guess the Tool ID.
Open WebUI patched a broken access control vulnerability in the Tool Valves endpoint in version 0.8.11. The flaw, later tracked as CVE-2026-34222, affected versions earlier than v0.8.11 and could expose sensitive valve data such as backend API keys to low-privileged users.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.