Incorrect authorization in Open WebUI - CVE-2026-87017
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive knowledge base metadata.
The vulnerability exists due to improper access control in the built-in knowledge search tool and affected vector backend search methods when searching knowledge bases through enabled built-in knowledge tools. A remote user can invoke the knowledge search tool to disclose sensitive knowledge base metadata.
Only deployments using an affected nondefault vector backend are vulnerable, and the exposure is limited to knowledge base identifiers, names, and descriptions rather than stored document text.