What is CVE-2026-70481?
A vulnerability in Open WebUI allowed any user with write access to a channel to update or delete messages without being the original author, affecting versions 0.5.0 through 0.11.0. Users should immediately update to the latest version to mitigate this issue.
Azərbaycanca: Open WebUI platformasında kanal mesajlarının yenilənməsi və silinməsi əməliyyatlarında zəiflik aşkar edilib: yazma icazəsi olan istənilən istifadəçi, mesajın müəllifi olmasa belə, onu redaktə edə və ya silə bilər. Bu, 0.5.0-dən 0.11.0-a qədər versiyalara təsir edir; istifadəçilərə dərhal yeni versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which operations are affected by the CVE-2026-70481 vulnerability in Open WebUI?
The vulnerability involves the update and delete operations of channel messages, where any user with write access could perform these actions without being the original message author.
Which versions of Open WebUI are affected by CVE-2026-70481?
Versions 0.5.0 through 0.11.0 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.