File Access Vulnerability in Open WebUI by Open WebUI
CVE-2026-54010

8.3HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
23 June 2026

What is CVE-2026-54010?

Open WebUI, an offline AI platform, has a critical flaw that allows authenticated users to attach arbitrary file IDs to their chat messages without verifying ownership. This enables attackers to share chat messages and obtain read access to sensitive files belonging to other users. The vulnerability was addressed in version 0.9.6, enhancing the security by ensuring proper ownership checks are enforced before file access.

Affected Version(s)

open-webui < 0.9.6

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.