CVE Tools

Open Webui

155 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Open Webui, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Open Webui CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Open Webui CVEs per month
MonthCVEs
2024-102
2024-110
2024-120
2025-010
2025-020
2025-036
2025-040
2025-052
2025-060
2025-070
2025-080
2025-090
2025-100
2025-112
2025-123
2026-010
2026-022
2026-034
2026-042
2026-0559
2026-0616
2026-0719
2026-0817
2026-0918

Severity

How the 155 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical21%
  • High6844%
  • Medium7850%
  • Low75%

Latest CVEs

The 15 most recently published vulnerabilities affecting Open Webui.

  1. CVE-2026-88006Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange6.5
  2. CVE-2026-88005Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange6.5
  3. CVE-2026-88002Open WebUI: Any authenticated user can hang the server via a cyclic chat message history6.5
  4. CVE-2026-88001Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets5.0
  5. CVE-2026-88000Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree6.5
  6. CVE-2026-87999Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch7.1
  7. CVE-2026-87998Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion7.1
  8. CVE-2026-87997Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions4.3
  9. CVE-2026-87996Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader7.7
  10. CVE-2026-87995Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin8.7
  11. CVE-2026-87994Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint4.3
  12. CVE-2026-87017Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends4.3
  13. CVE-2026-87016Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite8.1
  14. CVE-2026-87015Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication6.8
  15. CVE-2026-87014Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store