PatchSiren cyber security CVE debrief
CVE-2026-70484 open-webui CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:55.477Z and has not been modified since then. Open WebUI versions from 0.7.0 to 0.11.0 had a vulnerability allowing authenticated users with revoked image-generation permissions to access image providers through chat completions, risking API credits and storage. The likely operational impact of this vulnerability includes unauthorized access to image providers, potential misuse of API credits, and storage of generated files without proper authorization. The source-confidence limits of this vulnerability are based on the information provided in the CVE record and NVD detail, which indicate that the issue is fixed in version 0.11.0. However, further verification is needed to confirm the affected deployments and validate vendor guidance. Evidence limits suggest that additional review is required to ensure that all necessary information is documented and shared with relevant stakeholders.
- Vendor
- open-webui
- Product
- Unknown
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-04
- Original CVE updated
- 2026-08-05
- Advisory published
- 2026-08-04
- Advisory updated
- 2026-08-05
Who should care
Administrators and users of Open WebUI, especially those with image-generation features enabled, should review and update their deployments to version 0.11.0 or later. They should also verify image-generation permissions for all authenticated users and monitor chat completion activity for suspicious image provider access. Additionally, implementing compensating controls to limit API credits and storage usage is recommended for exposed systems while remediation is scheduled and verified. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Vulnerability management and security teams should prioritize reviewing compensating controls for exposed systems and verifying affected scope and severity through normal change control processes. Operators should focus on confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. Platform security teams should review relevant monitoring, detection, and logs for exposed assets that need extra review. Those responsible for asset inventory should ensure that all affected assets are accounted for and that appropriate actions are taken to mitigate the vulnerability. Change management processes should be used to plan vendor-supported updates or mitigations where exposure is confirmed. Those in charge of source tracking should verify the source grounding of the vulnerability and ensure that all necessary information is documented and shared with relevant stakeholders. Finally, security teams should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and implement necessary controls to prevent similar vulnerabilities in the future. The likely operational impact of this vulnerability includes unauthorized access to image providers, potential misuse of API credits, and storage of generated files without proper authorization. The source-confidence limits of this vulnerability are based on the information provided in the CVE record and NVD detail, which indicate that the issue is fixed in version 0.11.0. However, further verification is needed to confirm the
Technical summary
Open WebUI versions from 0.7.0 to 0.11.0 had a vulnerability allowing authenticated users with revoked image-generation permissions to access image providers through chat completions, risking API credits and storage. This issue arises from the legacy chat-completions features not re-checking the features.image_generation permission that direct image routes and native function-calling paths enforce.
Defensive priority
Authenticated users with revoked image-generation permissions could still access image providers through chat completions, risking API credits and storage.
Recommended defensive actions
- Review and update Open WebUI to version 0.11.0 or later
- Verify image-generation permissions for all authenticated users
- Monitor chat completion activity for suspicious image provider access
- Implement compensating controls to limit API credits and storage usage
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and NVD detail indicate that Open WebUI versions from 0.7.0 to 0.11.0 had a vulnerability allowing authenticated users with revoked image-generation permissions to access image providers through chat completions. The issue is fixed in version 0.11.0. Evidence limits suggest that further verification is needed to confirm affected deployments and validate vendor guidance.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:55.477Z and has not been modified since then.