Junglewise Threat Intelligence

CVE-2026-29070: PYSEC-2026-2693 - Open WebUI has unauthorized deletion of knowledge files

CVE-2026-29070 · Severity: low · CVSS 3.1 · Published 2026-07-13

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI is an open-source platform for managing and interacting with knowledge bases and AI models. A flaw in the file deletion function allows authenticated users to delete files from any knowledge base they have write access to, even if those files don't belong to them. An attacker can exploit this to destroy important documents or data stored by other users, disrupting operations and causing data loss.

Technical details

The vulnerability is a missing authorization check (CWE-862) in the `/knowledge/{id}/file/remove` API endpoint. The code validates that the user has write access to the target knowledge base, but fails to verify that the file being deleted actually belongs to that knowledge base. An authenticated attacker with write access to any knowledge base can delete arbitrary files from any other knowledge base by guessing or discovering file IDs. No user interaction or special privileges are required beyond basic authentication. The vulnerability affects all versions up to 0.8.5; a patch is available in version 0.8.6 and later.

Affected products

  • Open WebUI Open WebUI before 0.8.6

Timeline

  • 2026-03-27: disclosed
  • 2026-03-27: patched: Version 0.8.6 and later

References

Related threats