Information Disclosure Vulnerability in Open WebUI by Open WebUI
CVE-2026-29071
3.1LOW
What is CVE-2026-29071?
The Open WebUI platform has a vulnerability that enables authenticated users to access and read other users' private memories through the API endpoint /api/v1/retrieval/query/collection. This issue affects versions prior to 0.8.6. The vulnerability is critical as it compromises user privacy, allowing unauthorized access to sensitive information. The issue has been addressed in version 0.8.6, which patches the vulnerability and enhances the overall security of the platform.
Affected Version(s)
open-webui < 0.8.6
