PatchSiren cyber security CVE debrief
CVE-2026-70486 open-webui CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:55.747Z and has not been modified since then. The NVD entry is currently 8.2 HIGH. Open WebUI, an extensible and feature-rich AI platform, had a vulnerability in versions 0.9.0 to 0.11.0. The terminal file-preview serveUrl iframe allowed authenticated users to execute scripts in previewed HTML files. This could lead to account takeover and potential server-side code execution. The vulnerability was fixed in version 0.11.0. Admins and users, especially those with admin or workspace.function roles, should be aware and take action to protect their instances. Evidence from official CVE and NVD sources indicates a vulnerability in Open WebUI versions 0.9.0 to 0.11.0; further details limited. Users should verify their instances are patched and monitor for suspicious activity.
- Vendor
- open-webui
- Product
- Unknown
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-04
- Original CVE updated
- 2026-08-05
- Advisory published
- 2026-08-04
- Advisory updated
- 2026-08-05
Who should care
Admins and users of Open WebUI, especially those with admin or workspace.function roles, should be aware of this vulnerability and take action to protect their instances. Operators of Open WebUI deployments, security teams, and vulnerability management teams should prioritize patching and review compensating controls. Platform administrators and security personnel should monitor for suspicious activity and verify instance configurations.
Technical summary
Open WebUI versions 0.9.0 to 0.11.0 had a vulnerability in the terminal file-preview serveUrl iframe, allowing authenticated users to execute scripts in previewed HTML files, potentially leading to account takeover and server-side code execution. The vulnerability was fixed in version 0.11.0. Users with admin or workspace.function roles are at higher risk. Instances with exposed terminals are particularly vulnerable.
Defensive priority
Authenticated users with terminal access could be at risk; prioritize patching for admin and workspace.function holders.
Recommended defensive actions
- Patch Open WebUI to version 0.11.0 or later
- Restrict terminal access to authenticated users
- Monitor for suspicious activity on Open WebUI instances
- Consider compensating controls for admin and workspace.function holders
- Review Open WebUI instance configurations for secure terminal access
- Perform regular security audits on Open WebUI deployments
- Track and verify Open WebUI version updates in managed environments
Evidence notes
Evidence from official CVE and NVD sources indicates a vulnerability in Open WebUI versions 0.9.0 to 0.11.0; further details limited. The CVE record was published on 2026-08-04T20:16:55.747Z and has not been modified since then. The NVD entry is currently 8.2 HIGH. Additional review of Open WebUI documentation and changelogs did not reveal specific details on the patched version 0.11.0. Users should verify their instances are patched and monitor for suspicious activity.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:55.747Z and has not been modified since then.