Junglewise Threat Intelligence

CVE-2026-54006: Open WebUI IDOR in calendar event update

CVE-2026-54006 · Severity: medium · CVSS 4.3 · Published 2026-06-23

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI, a self-hosted AI platform, contains a flaw in its calendar system that allows users to inject events into other people's private calendars. By exploiting an authorization bypass, a regular user can move an event they created into a target's calendar if they know the target's calendar ID. This could be used for calendar spam, phishing attacks, or social engineering by making malicious links appear as legitimate personal appointments.

Technical details

An Insecure Direct Object Reference (IDOR) exists in the 'POST /api/v1/calendars/events/{event_id}/update' endpoint. While the application verifies that the requester has write access to the event's current calendar, it fails to validate the 'calendar_id' provided in the request body for the destination. An attacker with a 'user' role can create an event in their own calendar and then issue an update request to change the 'calendar_id' to a victim's ID. This bypasses the destination access checks performed during initial event creation. Successful exploitation allows for HTML injection (via sanitized DOMPurify) and calendar manipulation. The issue is fixed in version 0.9.6.

Affected products

  • open-webui open-webui < 0.9.6

Timeline

  • 2026-06-11: advisory: GitHub security advisory published
  • 2026-06-23: disclosed: CVE published to NVD
  • 2026-06-23: patched: Fix confirmed in version 0.9.6

References

Related threats