GHSA-2724-6cpj-gf3v: Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
HIGHHigh-risk vulnerability — CVSS 7.1
## Summary External knowledge connections are created and owned by administrators, and are shared by every external knowledge base bound to them. Deleting an external knowledge base also removed that connection from the instance configuration, with no check on the caller's role and no check for other knowledge bases still using it. …
CVE · detail
- CVE-2026-87998nvd ↗EPSS 0.27%
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected