THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-70481 (MEDIUM 5.4) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message. Becau

[NVD] CVE-2026-70481 (MEDIUM 5.4) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message. Becau

lownvdPublished 2026-08-04

CVE-2026-70481 CVSS: 5.4 MEDIUM Published: 2026-08-04T20:16:55.050

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrote the message. Because write access is the same grant a member needs to

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70481