Improper Validation of Specified Type of Input in Open WebUI - CVE-2026-87012
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service for calendar alerts.
The vulnerability exists due to improper validation of specified type of input in the upcoming-event lookup in the calendar event model when processing alert offsets from calendar event metadata. A remote user can create an upcoming calendar event with a non-numeric alert value to cause a denial of service for calendar alerts.
The event must fall within the scheduler's one-hour lookahead window.