CVE Tools

Openwebui

136 CVEs tracked since 2024. Since Oct 2024, none of them reached CISA KEV.

Openwebui CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Openwebui CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-1050
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03190
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05590
2026-06160
2026-07190
2026-08null or fewer
2026-09180

Products

The products that kept showing up in Openwebui's monthly top three, with their CVEs summed over those months.

  1. Open Webui1366 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Openwebui.

  1. CVE-2026-88006Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange6.5
  2. CVE-2026-88005Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange6.5
  3. CVE-2026-88002Open WebUI: Any authenticated user can hang the server via a cyclic chat message history6.5
  4. CVE-2026-88001Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets5.0
  5. CVE-2026-88000Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree6.5
  6. CVE-2026-87999Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch7.1
  7. CVE-2026-87998Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion7.1
  8. CVE-2026-87997Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions4.3
  9. CVE-2026-87996Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader7.7
  10. CVE-2026-87995Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin8.7
  11. CVE-2026-87994Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint4.3
  12. CVE-2026-87017Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends4.3
  13. CVE-2026-87016Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite8.1
  14. CVE-2026-87015Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication6.8
  15. CVE-2026-87014Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes6.5

The record

Peak rank
#14 in May 2026
Busiest month shown
May 2026, 59 CVEs
Months with a KEV entry
0 since Oct 2024
Monthly snapshots
6 since 2024
Openwebui's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store