Information disclosure in Open WebUI - CVE-2026-70491

 

Information disclosure in Open WebUI - CVE-2026-70491

Published: August 3, 2026


Vulnerability identifier: #VU140755
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-70491
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the tool read endpoints when handling requests for shared tools. A remote user can call the affected endpoints to disclose sensitive information.

Authentication and enabled plugins are required, and the issue affects tools shared with read access where the caller does not have write access.


Affected software

Open WebUI

How to mitigate CVE-2026-70491

Install security update from vendor's website.

Open WebUI - update to 0.11.0

External References

Related Security Bulletins