What is CVE-2026-70491?
CVE-2026-70491 is a vulnerability in Open WebUI self-hosted AI platform versions 0.10.2 and earlier. It allows authenticated non-admin users to access full Python tool source code via the GET /api/v1/tools/ endpoints. Users are advised to update to the latest version and review access controls.
Azərbaycanca: CVE-2026-70491, Open WebUI self-hosted AI platform-unun 0.10.2 və daha əvvəlki versiyalarında müəyyən edilmiş zəiflikdir. Bu zəiflik autentifikasiya olunmuş, lakin admin olmayan istifadəçilərin `/api/v1/tools/` endpoint-ləri vasitəsilə Python tool mənbə koduna icazəsiz giriş əldə etməsinə səbəb olur. İstifadəçilərə ən son versiyaya yeniləmə və giriş nəzarətlərini nəzərdən keçirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What platform is affected by CVE-2026-70491?
The vulnerability affects Open WebUI self-hosted AI platform versions 0.10.2 and earlier.
What data can an authenticated non-admin user access through this vulnerability?
An authenticated non-admin user can access the full Python tool source code.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.