File Access Vulnerability in Open WebUI by Open WebUI
CVE-2026-54010
8.3HIGH
What is CVE-2026-54010?
Open WebUI, an offline AI platform, has a critical flaw that allows authenticated users to attach arbitrary file IDs to their chat messages without verifying ownership. This enables attackers to share chat messages and obtain read access to sensitive files belonging to other users. The vulnerability was addressed in version 0.9.6, enhancing the security by ensuring proper ownership checks are enforced before file access.
Affected Version(s)
open-webui < 0.9.6
