---
id: CVE-2026-0766
title: >-
  Rejected reason: Open WebU's investigation further investigation showed that
  this is intended functionality of the Plugins extension system, in which users
  granted the relevant permission author Python that the server executes by
  design,…
summary: >-
  Rejected reason: Open WebU's investigation further investigation showed that
  this is intended functionality of the Plugins extension system, in which users
  granted the relevant permission author Python that the server executes by
  design,…
severity: none
published: '2026-01-23'
updated: '2026-09-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0766'
tags:
  - nvd
  - exploit-available
epss: 0.26035
epssPercentile: 0.97839
ingestedAt: '2026-09-02T18:48:48.472Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/bitt0n/CVE-2026-0766'
  checkedAt: '2026-09-08T15:36:50.609Z'
exploitAvailable: true
---

## Overview

Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue. https://docs.openwebui.com/security/vendor-dispositions/cve-2026-0766

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
