CVE-2026-87012Medium· 4.3▾ SunlitOpen WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the share…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
0.3% → 0.3%
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the shared upcoming-event scheduler compared that value numerically. An authenticated user with the calendar permission could store a non-numeric alert_minutes value that raised an exception and aborted the instance-wide alert pass, suppressing all users' reminders while the event remained in the lookahead window. This issue is fixed in version 0.11.1.
open_webui >= 0.9.0, < 0.11.1Upgrade past the affected range:
open_webui 0.11.1Affected packages:
open-webui >= 0.9.0, < 0.11.1Patched in:
open-webui 0.11.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87014Medium· 6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-87996High· 7.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-87016High· 8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-87997Medium· 4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-87011High· 7.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-88001Medium· 5.0Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform