CVE-2026-70482
Open WebUI · Open WebUI
Open WebUI is susceptible to an improper authentication flaw that can be exploited by an attacker via user interaction.
Executive summary
Open WebUI versions 0.8.0 through 0.10.x are vulnerable to an improper authentication flaw that could allow an attacker to gain unauthorized access to sensitive information.
Vulnerability
This is an improper authentication vulnerability (CWE-287) that requires user interaction and is exploitable by an unauthenticated attacker.
Business impact
The CVSS score of 8.1 reflects the high potential for data compromise or unauthorized administrative actions. Successful exploitation could allow an attacker to intercept sensitive data or perform actions on behalf of a victim, resulting in severe reputational or operational impact.
Remediation
Immediate Action: Update Open WebUI to version 0.11.0 or later to resolve the underlying authentication weakness.
Proactive Monitoring: Review application logs for suspicious authentication events or unexpected redirects that might indicate an attempt to exploit user-interaction-based vulnerabilities.
Compensating Controls: Educate users on the risks of clicking suspicious links and utilize browser-based security extensions to mitigate potential cross-site or interception-based attacks.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Upgrading to version 0.11.0 is the only reliable way to eliminate this risk. Due to the high CVSS score and the potential for unauthorized data access, this update should be prioritized in the next maintenance cycle.