THREAT OPS › Threat News › [NVD] CVE-2026-70481 (MEDIUM 5.4) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message. Becau
[NVD] CVE-2026-70481 (MEDIUM 5.4) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message. Becau
CVE-2026-70481 CVSS: 5.4 MEDIUM Published: 2026-08-04T20:16:55.050
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message. Because write access is the same grant a member needs to
Indicators of compromise
- CVE-2026-70481cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70481