5.4
CVE-2026-70481
- EPSS 0.3%
- Veröffentlicht 04.08.2026 20:16:55
- Zuletzt bearbeitet 18.09.2026 14:46:06
- Erkennungen
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message. Because write access is the same grant a member needs to post, any ordinary participant in a shared standard channel could rewrite or permanently delete another participant message, while group and direct message handlers enforced authorship. This issue is fixed in 0.11.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openwebui ≫ Open Webui Version >= 0.5.0 < 0.11.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.222 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/open-webui/open-webui/releases/tag/v0.11.0
https://github.com/open-webui/open-webui/commit/c609ec41154fa092fa0af80d9d365de06b666286
https://github.com/open-webui/open-webui/pull/27197
https://github.com/open-webui/open-webui/security/advisories/GHSA-mj5r-jf49-m3w7