Junglewise Threat Intelligence

CVE-2026-0766: Open WebUI plugin extension intended functionality

CVE-2026-0766 · Severity: info · Published 2026-01-23

Technologies: Open WebUI Open-Webui.

Executive brief

Open WebUI's plugin extension system allows authorized users to execute Python code on the server as part of its documented design. After investigation, this capability was confirmed to be intentional functionality rather than a security vulnerability, and users who have been granted the relevant permission can author and execute plugins as expected.

Technical details

This report was initially raised as a potential security concern but was rejected after vendor investigation. The issue relates to the plugin extension system in Open WebUI, which allows users with appropriate permissions to author and execute Python code server-side by design. This is intentional functionality of the extension system, not a vulnerability. No actual security flaw exists; the capability is documented and controlled through permission-based access.

Affected products

  • Open WebUI Open WebUI

Timeline

  • 2026-01-23: disclosed