Incorrect authorization in Open WebUI - #VU152707

 

Incorrect authorization in Open WebUI - #VU152707

Published: September 28, 2026


Vulnerability identifier: #VU152707
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose file contents and delete files.

The vulnerability exists due to incorrect authorization in the has_access_to_file access-control function when handling file-content and delete requests for files removed from knowledge bases. A remote user can request file content or delete a file using a known file ID to disclose file contents and delete files.

Exploitation requires that the file was last processed into the shared knowledge base, remains on the instance after removal, and that the owner removes it from that knowledge base.


Affected software

Open WebUI

Remediation

Install security update from vendor's website.

Open WebUI - update to 0.11.4

External References

Related Security Bulletins