Authorization bypass through user-controlled key in Open WebUI - CVE-2026-87994

 

Authorization bypass through user-controlled key in Open WebUI - CVE-2026-87994

Published: September 28, 2026


Vulnerability identifier: #VU152696
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-87994
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify another channel member's message while preserving the original author's identity.

The vulnerability exists due to missing authorization in the channel branch of the chat completions handler when processing a client-supplied message identifier for a channel. A remote user can submit a chat completion request targeting another member's message to modify another channel member's message while preserving the original author's identity.

Channels must be enabled, and exploitation requires write access to the target channel and knowledge of the target message identifier.


Affected software

Open WebUI

How to mitigate CVE-2026-87994

Install security update from vendor's website.

Open WebUI - update to 0.11.1

External References

Related Security Bulletins