Authorization bypass through user-controlled key in Open WebUI - CVE-2026-87994
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to modify another channel member's message while preserving the original author's identity.
The vulnerability exists due to missing authorization in the channel branch of the chat completions handler when processing a client-supplied message identifier for a channel. A remote user can submit a chat completion request targeting another member's message to modify another channel member's message while preserving the original author's identity.
Channels must be enabled, and exploitation requires write access to the target channel and knowledge of the target message identifier.