PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-70487 open-webui CVE debrief

CVE-2026-70487 debrief based on CVE Program and NVD records. Open WebUI 0.8.8 to 0.10.0 allows read-only cross-user confidentiality loss via knowledge attachments. Fixed in 0.11.0. The vulnerability allows authenticated users to access knowledge attachments from other users, potentially leading to read-only cross-user confidentiality loss. Open WebUI administrators and security teams should assess exposure, verify inventory, and prioritize patching to version 0.11.0. The issue is fixed in version 0.11.0, which addresses the vulnerability by properly filtering client-supplied knowledge attachments against the caller's read access.

Vendor
open-webui
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-04
Original CVE updated
2026-09-18
Advisory published
2026-08-04
Advisory updated
2026-09-18

Who should care

Open WebUI administrators, security teams, and users with access to knowledge attachments. These stakeholders should assess exposure, verify inventory, and prioritize patching to version 0.11.0. Additionally, they should review compensating controls for exposed systems and verify user permissions.

Why it matters

CVE-2026-70487 allows authenticated users to access knowledge attachments from other users in Open WebUI, leading to read-only cross-user confidentiality loss. Open WebUI administrators and security teams should assess exposure, verify inventory, and prioritize patching to version 0.11.0.

  • Read-only cross-user confidentiality loss
  • Potential data exposure through knowledge attachments
  • Need for verification of user permissions and access controls
  • Priority for patching Open WebUI instances to version 0.11.0

Technical summary

Open WebUI 0.8.8 to 0.10.0 allows authenticated users to access knowledge attachments from other users via file ID, leading to read-only cross-user confidentiality loss. Fixed in 0.11.0. The vulnerability is caused by the acceptance of client-supplied knowledge attachments without filtering them against the caller's read access. This issue can be mitigated by upgrading to version 0.11.0 or later. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. There are no known instances of exploitation. The Open WebUI project has addressed the issue in version 0.11.0.

Defensive priority

Assess exposure, verify inventory, and prioritize patching for Open WebUI instances.

Recommended defensive actions

  • Assess Open WebUI instance exposure and prioritize patching to version 0.11.0
  • Verify inventory of Open WebUI instances and check for indicators of compromise
  • Restrict access to knowledge attachments and validate user permissions
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

CVE Program and NVD records detail Open WebUI vulnerability. Limited details on exploitation or impact. The CVE record was published on 2026-08-04T21:16:37.480Z and has not been modified since then. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. There are no known instances of exploitation. The Open WebUI project has addressed the issue in version 0.11.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-70487 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-70487

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-70487 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70487

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.