Missing Authentication for Critical Function in Open WebUI - CVE-2026-59715

 

Missing Authentication for Critical Function in Open WebUI - CVE-2026-59715

Published: July 3, 2026


Vulnerability identifier: #VU136844
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59715
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to manipulate collaborative document session state.

The vulnerability exists due to missing authentication for critical function in the Socket.IO Ydoc event handlers `ydoc:awareness:update` and `ydoc:document:leave` when handling WebSocket events for collaborative document sessions. A remote user can send crafted Socket.IO events with spoofed user identifiers to manipulate collaborative document session state.

This can be used to spoof user presence and cursor awareness data in document rooms, and to broadcast false user-left events.


Affected software

Open WebUI

How to mitigate CVE-2026-59715

Install security update from vendor's website.

Open WebUI - update to 0.10.0

External References

Related Security Bulletins