PatchSiren cyber security CVE debrief
CVE-2026-70488 open-webui CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. Open WebUI, a self-hosted AI platform, had a vulnerability from version 0.9.6 to 0.11.0. The sync cleanup endpoint allowed users with write access to one knowledge base to delete directories and remove file embeddings from another knowledge base, potentially causing documents to disappear from search results and breaking chat functionality for specific documents. This issue could lead to data integrity issues if exploited. The vulnerability is fixed in version 0.11.0. Administrators and users should be aware of this vulnerability and take necessary actions to protect their instances. This includes updating to the latest version and restricting write access to knowledge bases to authorized users only. Security teams should also monitor for suspicious activity related to knowledge base modifications. The CVE record was published on 2026-08-04T21:16:37.623Z and has not been modified since then.
- Vendor
- open-webui
- Product
- Unknown
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-04
- Original CVE updated
- 2026-08-05
- Advisory published
- 2026-08-04
- Advisory updated
- 2026-08-05
Who should care
Administrators and users of Open WebUI, especially those with write access to knowledge bases, should be aware of this vulnerability and take necessary actions to protect their instances. This includes updating to the latest version and restricting write access to knowledge bases to authorized users only. Security teams should also monitor for suspicious activity related to knowledge base modifications.
Technical summary
Open WebUI, a self-hosted AI platform, had a vulnerability from version 0.9.6 to 0.11.0. The sync cleanup endpoint allowed users with write access to one knowledge base to delete directories and remove file embeddings from another knowledge base, potentially causing documents to disappear from search results and breaking chat functionality for specific documents. This issue could lead to data integrity issues if exploited. The vulnerability is fixed in version 0.11.0.
Defensive priority
Organizations using Open WebUI versions between 0.9.6 and 0.11.0 should prioritize patching to prevent potential data integrity issues.
Recommended defensive actions
- Apply the patch by updating Open WebUI to version 0.11.0 or later
- Restrict write access to knowledge bases to authorized users only
- Monitor for suspicious activity related to knowledge base modifications
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in Open WebUI. The issue is fixed in version 0.11.0. Users with write access to one knowledge base could delete directories and remove file embeddings from another knowledge base. This could cause documents to drop out of retrieval results and break chat-with-file for targeted documents without disclosing contents. The vulnerability was introduced in version 0.9.6 and fixed in 0.11.0. Administrators should verify their instances and ensure they are running the latest version.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T21:16:37.623Z and has not been modified since then.