What is CVE-2026-70479?
CVE-2026-70479 is a vulnerability in Open WebUI (versions 0.9.6 to 0.11.0) where, with WEB_LOADER_ENGINE=playwright, only top-level page requests are validated, allowing sub-resource requests to bypass checks. This can be exploited by an authenticated user to access internal resources. Users should upgrade to the latest version to mitigate the risk.
Azərbaycanca: CVE-2026-70479, Open WebUI platformasında (0.9.6-0.11.0 versiyaları) WEB_LOADER_ENGINE=playwright rejimində aşkarlanmış zəiflikdir. Autentifikasiyalı istifadəçi tərəfindən təqdim edilmiş səhifənin sub-resource sorğularının yoxlanılmaması səbəbindən serverdaxili resurslara icazəsiz giriş (SSRF) mümkündür. Təhlükəsizlik üçün platformanı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of Open WebUI are affected by CVE-2026-70479?
The vulnerability affects Open WebUI versions 0.9.6 through 0.11.0.
What type of attack can an authenticated user perform by exploiting CVE-2026-70479?
An authenticated user can perform unauthorized access to internal resources (SSRF).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.