THREAT OPS › Threat News › [GHSA] GHSA-2724-6cpj-gf3v (high) — Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
[GHSA] GHSA-2724-6cpj-gf3v (high) — Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
GHSA-2724-6cpj-gf3v Severity: high CVE: CVE-2026-87998
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
## Summary External knowledge connections are created and owned by administrators, and are shared by every external knowledge base bound to them. Deleting an external knowledge base also removed that connection from the instance conf
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-87998cve
Original source: https://github.com/advisories/GHSA-2724-6cpj-gf3v