Image Generation Permission Bypass in Open WebUI by Open WebUI
CVE-2026-70484
4.3MEDIUM
What is CVE-2026-70484?
Open WebUI, a user-friendly self-hosted AI platform, has a vulnerability where an authenticated user can bypass revoked image-generation permissions. Versions from 0.7.0 to 0.10.0 are affected, allowing users to access image generation functionalities even when they should no longer have the capability. This results in potential misuse of API credits and provider quotas without compromising sensitive credentials. The issue has been resolved in version 0.11.0, emphasizing the importance of keeping software updated.
Affected Version(s)
open-webui >= 0.7.0, < 0.11.0
