What is CVE-2026-70484?
The CVE-2026-70484 vulnerability in Open WebUI allows unauthorized image generation via the legacy chat-completions feature, which trusts a client-supplied image_generation flag without re-checking permissions. This affects self-hosted AI platforms from version 0.7.0 to 0.11.0. Users should immediately update or harden access controls.
Azərbaycanca: Open WebUI platformasında aşkar edilmiş CVE-2026-70484 zəifliyi, köhnə chat-completions funksiyasının müştəri tərəfindən göndərilən image_generation bayrağını düzgün yoxlamaması nəticəsində icazəsiz şəkil yaratma əməliyyatlarına imkan verir. Bu, 0.7.0-dən 0.11.0 versiyalarına qədər olan öz-özünə yerləşdirilən (self-hosted) AI platformalarına təsir edir. İstifadəçilər dərhal platformanı güncəlləməli və ya giriş nəzarətlərini sərtləşdirməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of Open WebUI are affected by CVE-2026-70484?
The CVE-2026-70484 vulnerability affects self-hosted AI platforms running Open WebUI from version 0.7.0 to 0.11.0.
What should users do to protect against CVE-2026-70484?
To protect against CVE-2026-70484, users should immediately update the platform or harden access controls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.