Image Generation Permission Bypass in Open WebUI by Open WebUI
CVE-2026-70484

4.3MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
4 August 2026

What is CVE-2026-70484?

Open WebUI, a user-friendly self-hosted AI platform, has a vulnerability where an authenticated user can bypass revoked image-generation permissions. Versions from 0.7.0 to 0.10.0 are affected, allowing users to access image generation functionalities even when they should no longer have the capability. This results in potential misuse of API credits and provider quotas without compromising sensitive credentials. The issue has been resolved in version 0.11.0, emphasizing the importance of keeping software updated.

Affected Version(s)

open-webui >= 0.7.0, < 0.11.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.