8.8
CVE-2026-0766
- EPSS 27.23%
- Veröffentlicht 23.01.2026 03:28:35
- Zuletzt bearbeitet 02.09.2026 18:18:47
- Erkennungen
Open WebUI load_tool_module_by_id Command Injection Remote Code Execution Vulnerability
Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue. https://docs.openwebui.com/security/vendor-dispositions/cve-2026-0766
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerOpen WebUI
≫
Produkt
Open WebUI
Default Statusunknown
Version
0.6.32
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 27.23% | 0.978 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|