Junglewise Threat Intelligence

CVE-2026-59714: Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can o

CVE-2026-59714 · Severity: high · CVSS 7.1 · Published 2026-08-13

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

An authenticated user can overwrite messages in any chat channel, including private and direct messages they do not have permission to access. This allows an attacker to change the content of existing messages while making it appear as though the original author wrote them, potentially leading to misinformation or impersonation within the platform.

Technical details

A missing authorization check in the chat completion API allows authenticated users to overwrite messages across different channels. When a request uses a 'channel:'-prefixed chat_id, the application skips ownership verification and passes user-supplied message IDs directly to a database update function. This function, `_make_channel_emitter`, performs updates based on the primary key without verifying if the message belongs to the specified channel or if the user has access to it. This affects both single-model requests and multimodel requests using the `message_ids` map. The vulnerability is patched in version 0.10.0 by implementing per-entry validation and a fail-closed emitter that verifies channel ownership before writing.

Affected products

  • Open WebUI open-webui >= 0.9.5, < 0.10.0

Timeline

  • 2026-07-02: disclosed: Initial disclosure on GitHub
  • 2026-07-24: advisory: GitHub Advisory published
  • 2026-07-24: patched: Fix confirmed in version 0.10.0

References

Related threats