What is CVE-2026-70487?
CVE-2026-70487 is a vulnerability in Open WebUI where inline direct model metadata allowed client-supplied knowledge attachments without filtering read access, enabling any authenticated user to access another user's files by knowing their file ID. Versions 0.8.8 to 0.11.0 are affected; users must update immediately.
Azərbaycanca: Open WebUI platformasında tapılan CVE-2026-70487 zəifliyi autentifikasiya olunmuş istənilən istifadəçiyə başqa istifadəçinin fayl identifikatorunu bilməklə həmin fayla icazəsiz giriş imkanı verir. 0.8.8-dən 0.11.0-a qədər versiyalar təsirlənir, dərhal son versiyaya yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Open WebUI
FAQ2
What threat does CVE-2026-70487 pose in the Open WebUI platform?
This vulnerability allows any authenticated user to access another user's files without authorization by knowing their file ID.
Which versions of Open WebUI are affected by CVE-2026-70487?
Versions 0.8.8 to 0.11.0 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.