Open WebUI Vulnerability in AI Self-Hosted Platform
CVE-2026-87999

7.1HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
9 September 2026

What is CVE-2026-87999?

The Open WebUI platform, which serves as a self-hosted AI solution, suffered from a vulnerability where its API endpoints, specifically /api/v1/retrieval/process/web and /api/v1/retrieval/process/web/search, incorrectly treated certain globally routable IP addresses as external proof of destination. This flaw allowed authenticated users to exploit Azure-hosted instances, enabling them to fetch and return data from not only 168.63.129.16 but also from other restricted IP ranges. This issue has been addressed in version 0.11.1.

Affected Version(s)

open-webui < 0.11.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.