Information disclosure in Open WebUI - #VU140755

 

Information disclosure in Open WebUI - #VU140755

Published: August 3, 2026


Vulnerability identifier: #VU140755
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the tool read endpoints when handling requests for shared tools. A remote user can call the affected endpoints to disclose sensitive information.

Authentication and enabled plugins are required, and the issue affects tools shared with read access where the caller does not have write access.


Affected software

Open WebUI

Remediation

Install security update from vendor's website.

Open WebUI - update to 0.11.0

External References

Related Security Bulletins