Cross-User Confidentiality Issue in Open WebUI by Open WebUI
CVE-2026-70487
5.3MEDIUM
What is CVE-2026-70487?
Open WebUI is a self-hosted AI platform that permits users to perform operations with model metadata. However, versions 0.8.8 to 0.11.0 contain a vulnerability that allows authenticated users to access knowledge attachments without proper access control. Specifically, if a user is aware of another user's file ID, they could exploit the built-in knowledge tools to retrieve sensitive information from that file. This loophole compromises user privacy and allows unauthorized reading of information across users, while not affecting the overall permissions set on the knowledge base or the validation of saved workspace models. The issue has been resolved in version 0.11.0.
Affected Version(s)
open-webui >= 0.8.8, < 0.11.0
