Open WebUI Vulnerability in Deletion Process for Knowledge Base by Vendor Open WebUI
CVE-2026-87998

7.1HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
9 September 2026

What is CVE-2026-87998?

Open WebUI, a self-hosted AI platform, contains a vulnerability that allows unauthorized deletion of knowledge base entries. Specifically, in versions 0.10.0 to 0.11.1, an endpoint for deleting knowledge base entries fails to verify administrator privileges adequately. This oversight permits non-administrators with write access to delete shared configurations, rendering dependent knowledge bases inaccessible. The issue has been resolved in version 0.11.1.

Affected Version(s)

open-webui >= 0.10.0, < 0.11.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.