Incorrect authorization in Open WebUI - CVE-2026-87017

 

Incorrect authorization in Open WebUI - CVE-2026-87017

Published: September 28, 2026


Vulnerability identifier: #VU152695
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-87017
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive knowledge base metadata.

The vulnerability exists due to improper access control in the built-in knowledge search tool and affected vector backend search methods when searching knowledge bases through enabled built-in knowledge tools. A remote user can invoke the knowledge search tool to disclose sensitive knowledge base metadata.

Only deployments using an affected nondefault vector backend are vulnerable, and the exposure is limited to knowledge base identifiers, names, and descriptions rather than stored document text.


Affected software

Open WebUI

How to mitigate CVE-2026-87017

Install security update from vendor's website.

Open WebUI - update to 0.11.1

External References

Related Security Bulletins