{"id":"CVE-2026-0765","title":"Rejected reason: Open WebU's investigation further investigation  showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design…","summary":"Rejected reason: Open WebU's investigation further investigation  showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design…","severity":"none","published":"2026-01-23","updated":"2026-09-02","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-0765","tags":["nvd"],"epss":0.01603,"epssPercentile":0.74148,"ingestedAt":"2026-09-02T18:48:48.429Z","slug":"CVE-2026-0765","body":"## Overview\n\nRejected reason: Open WebU's investigation further investigation  showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue. https://docs.openwebui.com/security/vendor-dispositions/cve-2026-0765\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}