CVE-2026-56399 Details
Description
Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal services and potentially execute commands via instance secrets.
A server-side request forgery (SSRF) vulnerability has been identified in Open WebUI versions prior to 0.6.27. The issue resides in the '/api/v1/retrieval/process/web' endpoint, where authenticated users can bypass existing SSRF protections. By manipulating URL parameters with location redirect headers, attackers may access internal services and potentially execute commands using instance secrets.
Users can update to Open WebUI version 0.6.27 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/open-webui/open-webui/security/advisories/GHSA-82r6-c5jm-f3mw | CISA-ADP | AdvisoryBundleExploitRemedyVendor |
| https://github.com/open-webui/open-webui/commit/02238d3113e966c353fce18f1b65117380896774 | [email protected] | Source CodeVendor |
| https://github.com/open-webui/open-webui/security/advisories/GHSA-82r6-c5jm-f3mw | [email protected] | AdvisoryBundleExploitRemedyVendor |
| https://www.vulncheck.com/advisories/open-webui-server-side-request-forgery-via-location-redirect-in-api-v1-retrieval-process-web | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Open WebUI | <= 0.6.26 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion