CVE-2026-70487 Details
Description
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering them against the caller's read access. Any authenticated user who knew another user's file id could have the builtin knowledge tools return indexed chunks from that file, causing a read-only cross-user confidentiality loss while leaving knowledge-base permissions and saved workspace model validation unaffected. This issue is fixed in 0.11.0.
A vulnerability in Open WebUI versions 0.8.8 through 0.10.2 allows authenticated users to access indexed content from another user's files through the chat completion API. This issue arises because the application accepted client-supplied knowledge attachments without verifying the caller's read permissions. As a result, any user with knowledge of a file ID could retrieve its contents, leading to unauthorized cross-user file access. The vulnerability is read-only and does not affect knowledge base permissions or saved workspace model validations.
Users can upgrade to Open WebUI version 0.11.0 or later, where this vulnerability has been fixed. The update ensures that an inline model's attached knowledge is filtered against the caller's read access before being utilized, thereby preventing unauthorized file content access.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openwebui open webui | >= 0.8.8, < 0.11.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | Initial Analysis | [email protected] |
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | New CVE Received | [email protected] |