Information Disclosure Vulnerability in Open WebUI by Open WebUI
CVE-2026-29071

3.1LOW

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
26 March 2026

What is CVE-2026-29071?

The Open WebUI platform has a vulnerability that enables authenticated users to access and read other users' private memories through the API endpoint /api/v1/retrieval/query/collection. This issue affects versions prior to 0.8.6. The vulnerability is critical as it compromises user privacy, allowing unauthorized access to sensitive information. The issue has been addressed in version 0.8.6, which patches the vulnerability and enhances the overall security of the platform.

Affected Version(s)

open-webui < 0.8.6

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.