User Authorization Flaw in Open WebUI AI Platform
CVE-2026-87994
4.3MEDIUM
What is CVE-2026-87994?
Open WebUI versions 0.9.5 to 0.11.1 contain a vulnerability where the chat_completion endpoint fails to properly verify that a user is the author of a message before allowing modifications to it. This allows any channel member to replace messages authored by others while maintaining the original author's identity, posing a threat to the integrity of conversation records. The flaw has been rectified in version 0.11.1.
Affected Version(s)
open-webui >= 0.9.5, < 0.11.1
