THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-70488 (MEDIUM 4.3) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids supplied in the request body without checking

[NVD] CVE-2026-70488 (MEDIUM 4.3) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids supplied in the request body without checking

lownvdPublished 2026-08-04

CVE-2026-70488 CVSS: 4.3 MEDIUM Published: 2026-08-04T21:16:37.623

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids supplied in the request body without checking that those objects belonged to that knowledge base.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70488