What is CVE-2026-70488?
CVE-2026-70488 is a vulnerability in the self-hosted AI platform Open WebUI. In versions 0.9.6 through 0.11.0, the sync cleanup endpoint incorrectly authorizes write access based on the URL, but then acts on file and directory IDs from the request body without proper checks, allowing unauthorized deletion of arbitrary files. Users should update to the latest version immediately.
Azərbaycanca: CVE-2026-70488 Open WebUI öz-özünə host edilən AI platformasında aşkarlanmış boşluqdur. 0.9.6-dan 0.11.0-a qədər versiyalarda "sync cleanup endpoint" yazma icazəsini yanlış yoxlayır, nəticədə autentifikasiyasız istifadəçi URL-də olmayan fərqli fayl və direktoriyaları silə bilər. İstifadəçilərə platformanı dərhal yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What functionality of Open WebUI is affected by CVE-2026-70488?
The vulnerability affects the sync cleanup endpoint, which incorrectly authorizes write access based on the URL but allows deletion of files and directories from the request body without proper checks.
Which versions of Open WebUI are vulnerable to CVE-2026-70488?
Versions 0.9.6 through 0.11.0 are affected. Users should update to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.