CVE-2026-70481Medium· 5.4▾ TwilightPoC availableOpen WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checki…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.7 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
1 GitHub repo
Last analysed / modified upstream
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message. Because write access is the same grant a member needs to post, any ordinary participant in a shared standard channel could rewrite or permanently delete another participant message, while group and direct message handlers enforced authorship. This issue is fixed in 0.11.0.
open_webui >= 0.5.0, < 0.11.0Upgrade past the affected range:
open_webui 0.11.0Affected packages:
open-webui >= 0.5.0, <= 0.10.2Patched in:
open-webui 0.11.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-70494High· 8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-70483Low· 3.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-70484Medium· 4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-70487Medium· 5.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-87997Medium· 4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-87994Medium· 4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform