THREAT OPS › Threat News › [NVD] CVE-2026-70488 (MEDIUM 4.3) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids supplied in the request body without checking
[NVD] CVE-2026-70488 (MEDIUM 4.3) — Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids supplied in the request body without checking
CVE-2026-70488 CVSS: 4.3 MEDIUM Published: 2026-08-04T21:16:37.623
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids supplied in the request body without checking that those objects belonged to that knowledge base.
Indicators of compromise
- CVE-2026-70488cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70488