CVE-2026-34222
- EPSS 5.27%
- Veröffentlicht 01.04.2026 17:02:21
- Zuletzt bearbeitet 15.04.2026 15:25:35
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access control vulnerability in tool values. This issue has been patched in version 0.8.11.
CVE-2026-29071
- EPSS 0.25%
- Veröffentlicht 26.03.2026 23:54:38
- Zuletzt bearbeitet 01.04.2026 16:09:53
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, any authenticated user can read other users' private memories via `/api/v1/retrieval/query/collection`. Version 0.8.6 patches t...
CVE-2026-29070
- EPSS 0.25%
- Veröffentlicht 26.03.2026 23:39:33
- Zuletzt bearbeitet 01.04.2026 16:10:43
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an access control check is missing when deleting a file from a knowledge base. The only check being done is that the user has w...
CVE-2026-28788
- EPSS 2.86%
- Veröffentlicht 26.03.2026 23:38:20
- Zuletzt bearbeitet 01.04.2026 16:12:25
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, any authenticated user can overwrite any file's content by ID through the `POST /api/v1/retrieval/process/files/batch` endpoint...
CVE-2026-28786
- EPSS 0.43%
- Veröffentlicht 26.03.2026 23:37:25
- Zuletzt bearbeitet 30.03.2026 17:25:24
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an unsanitized filename field in the speech-to-text transcription endpoint allows any authenticated non-admin user to trigger a...
CVE-2026-26193
- EPSS 0.19%
- Veröffentlicht 19.02.2026 19:15:03
- Zuletzt bearbeitet 20.02.2026 20:15:37
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.44, aanually modifying chat history allows setting the `embeds` property on a response message, the content of which is loaded int...
CVE-2026-26192
- EPSS 0.19%
- Veröffentlicht 19.02.2026 19:10:52
- Zuletzt bearbeitet 20.02.2026 20:17:25
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.7.0, aanually modifying chat history allows setting the `html` property within document metadata. This causes the frontend to enter ...
CVE-2026-0767
- EPSS 0.24%
- Veröffentlicht 23.01.2026 03:28:39
- Zuletzt bearbeitet 02.09.2026 18:19:00
Rejected reason: Open WebU's investigation showed that this describes the behavior of plain HTTP rather than a defect in the product. TLS termination is the operator's deployment decision, as it is for any backend that speaks HTTP, and not a security...
CVE-2026-0766
- EPSS 27.23%
- Veröffentlicht 23.01.2026 03:28:35
- Zuletzt bearbeitet 02.09.2026 18:18:47
Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a se...
CVE-2026-0765
- EPSS 1.69%
- Veröffentlicht 23.01.2026 03:28:32
- Zuletzt bearbeitet 02.09.2026 18:18:14
Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a s...