What is CVE-2026-70483?
CVE-2026-70483 is a vulnerability in Open WebUI, affecting versions 0.9.6 to 0.11.0. The DELETE /api/v1/chats/{id} endpoint cancels a chat's in-flight tasks before verifying deletion permissions, allowing any authenticated user to abort another user's tasks by knowing the chat ID. Users should update to the latest patched version.
Azərbaycanca: CVE-2026-70483 Open WebUI platformasında aşkarlanmış zəiflikdir. 0.9.6-dan 0.11.0 versiyalarına qədər autentifikasiya olunmuş istənilən istifadəçi, başqa bir istifadəçinin chat ID-sini bilməklə həmin chat üzrə icra olunan tapşırıqları dayandıra bilər. İstifadəçilərə platformanı ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What versions of Open WebUI are affected by CVE-2026-70483?
This vulnerability affects Open WebUI versions from 0.9.6 to 0.11.0.
What action can an authenticated user perform by exploiting this vulnerability?
Any authenticated user can abort another user's in-flight tasks by knowing the chat ID, without having deletion permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.