Vulnerability in Open WebUI AI Platform Affects User Privacy and Security
CVE-2026-87017

4.3MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
9 September 2026

What is CVE-2026-87017?

The Open WebUI AI platform contains a vulnerability whereby the built-in knowledge search tool fails to properly enforce a metadata filter across multiple vector backends. This allows authenticated users on certain affected backends to enumerate identifiers, names, and descriptions of knowledge bases that should otherwise remain inaccessible. This leakage of information could potentially expose sensitive details about available knowledge collections, while document text remains segmented in separate collections. The issue has been addressed in version 0.11.1.

Affected Version(s)

open-webui >= 0.7.0, < 0.11.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.