Skip to content
archivevulnerability · 10 Sep 2026 · 15:09 UTC

GHSA-2724-6cpj-gf3v: Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion

VULNCVE-2026-87998source · GTH
HIGHHigh-risk vulnerability — CVSS 7.1

last 60 dispatches · spectrum

## Summary External knowledge connections are created and owned by administrators, and are shared by every external knowledge base bound to them. Deleting an external knowledge base also removed that connection from the instance configuration, with no check on the caller's role and no check for other knowledge bases still using it. …

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected