Known vulnerabilities in Open WebUI 0.10.1

Vendor: Open WebUI
Software: Open WebUI
Version: 0.10.1
Software CPE: cpe:2.3:a:open_webui:ollama_webui:*:*:*:*:*:*:*:*
Total vulnerabilities: 12
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 7.2

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Open WebUI version 0.10.1 Open WebUI 0.10.1 is affected by 12 vulnerabilities: 12 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU136852 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-59221
CWE-22 Low
No
No
0.10.0 03.07.2026 SB2026063040
#VU136851 - Missing Authorization
CVE-2026-59225
CWE-862 Low
No
No
0.10.0 03.07.2026 SB2026063040
#VU136850 - Exposure of sensitive information to an unauthorized actor
CVE-2026-59222
CWE-200 Low
No
No
0.10.0 03.07.2026 SB2026063040
#VU136846 - Improper Access Control
CVE-2026-59213
CWE-284 Low
No
No
0.10.0 03.07.2026 SB2026063040
#VU136845 - Incorrect Authorization
CVE-2026-59212
CWE-863 Low
No
No
0.10.0 03.07.2026 SB2026063040
#VU136844 - Missing Authentication for Critical Function
CVE-2026-59715
CWE-306 Low
No
No
0.10.0 03.07.2026 SB2026063040
#VU136843 - Missing Authorization
CWE-862 Low
No
No
0.10.0 03.07.2026 SB2026063040
#VU136842 - Improper Authorization
CVE-2026-59219
CWE-285 Low
No
No
0.10.0 03.07.2026 SB2026063040
#VU135957 - Inefficient Regular Expression Complexity
CVE-2026-59220
CWE-1333 Low
No
No
0.10.0 30.06.2026 SB2026063040
#VU135956 - Incorrect Authorization
CVE-2026-59227
CWE-863 Low
No
No
0.10.0 30.06.2026 SB2026063040
#VU135954 - Improper Authorization
CVE-2026-59226
CWE-285 Low
No
No
0.10.0 30.06.2026 SB2026063040
#VU135955 - Incorrect Authorization
CWE-863 Low
No
No
0.10.0 30.06.2026 SB2026063040