CVE-2026-70482

Open WebUI · Open WebUI

Open WebUI is susceptible to an improper authentication flaw that can be exploited by an attacker via user interaction.

Executive summary

Open WebUI versions 0.8.0 through 0.10.x are vulnerable to an improper authentication flaw that could allow an attacker to gain unauthorized access to sensitive information.

Vulnerability

This is an improper authentication vulnerability (CWE-287) that requires user interaction and is exploitable by an unauthenticated attacker.

Business impact

The CVSS score of 8.1 reflects the high potential for data compromise or unauthorized administrative actions. Successful exploitation could allow an attacker to intercept sensitive data or perform actions on behalf of a victim, resulting in severe reputational or operational impact.

Remediation

Immediate Action: Update Open WebUI to version 0.11.0 or later to resolve the underlying authentication weakness.

Proactive Monitoring: Review application logs for suspicious authentication events or unexpected redirects that might indicate an attempt to exploit user-interaction-based vulnerabilities.

Compensating Controls: Educate users on the risks of clicking suspicious links and utilize browser-based security extensions to mitigate potential cross-site or interception-based attacks.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Upgrading to version 0.11.0 is the only reliable way to eliminate this risk. Due to the high CVSS score and the potential for unauthorized data access, this update should be prioritized in the next maintenance cycle.