CVE-2026-26192Disclosure(openwebui / open_webui)

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch openwebui open_webui systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.7.0, aanually modifying chat history allows setting the `html` property within document metadata. This causes the frontend to enter a code path that treats document contents as HTML, and render them in an iFrame when the citation is previewed. This allows stored XSS via a weaponized document payload in a chat. The payload also executes when the citation is viewed on a shared chat. Version 0.7.0 fixes the issue.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open_webui

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 13 mentions across 12 observed days
  • Momentum state: rising

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 13 signals
  • Disclosure: 11 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-18)
  • 13 total mentions across 12 days

Affected systems

Vendors
Products
open_webui

Deep dive

Activity timeline13 mentions / 12d
01122Mentions · 2026-03-07: 1Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-18: 2PoC Mentioned / Linked · 2026-03-16: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-14: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 203-0703-0803-0903-1003-1103-1203-1303-1403-1503-1603-1703-18
Signal classification3 categories
Disclosure
1184.6%
Patch
17.7%
General
17.7%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-071
Disclosure1
2026-03-081
Patch1
2026-03-091
Disclosure1
2026-03-101
Disclosure1
2026-03-111
General1
2026-03-121
Disclosure1
2026-03-131
Disclosure1
2026-03-141
Disclosure1
2026-03-151
Disclosure1
2026-03-161
Disclosure1
2026-03-171
Disclosure1
2026-03-182
Disclosure2
Full discourse13 posts
  • Prateek Tomar@Prateektomar
    Disclosure

    New vulnerability disclosed: CVE-2026-26192 with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Worth reviewing if this affects your stack. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    A new vulnerability, CVE-2026-26192, has been disclosed with a CVSS score of 7.3 affecting Open WebUI; no PoC, exploit, or patch information is provided.

    0001042
    93 followersView on X
  • Prateek Tomar@Prateektomar
    General

    CVE-2026-26192 has been published with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Add it to your patching queue if applicable. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    CVE-2026-26192 has been disclosed with a CVSS score of 7.3, and the advisory recommends adding it to the patching queue, though specific mitigation steps are not detailed.

    0001069
    95 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    Security advisory: CVE-2026-26192 with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Check if you need to take action. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    The advisory announces CVE‑2026‑26192 with a 7.3 CVSS score for Open WebUI, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0001056
    92 followersView on X
  • ナタリー 🌙@natalie_avfieb
    Disclosure

    Open WebUI CVE-2026-26192: CVSS 7.3. Self-hosted AI interfaces are becoming a new attack surface. When you host your own LLM UI, you’re also hosting your own vulnerability management. Not everyone is ready for that responsibility.

    Post summary

    The text announces CVE‑2026‑26192 for Open WebUI, noting a CVSS score of 7.3 and cautioning that self‑hosted AI interfaces present a new attack surface.

    0000054
    84 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    CVE-2026-26192 has been published with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Add it to your patching queue if applicable. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    CVE-2026-26192 has been publicly disclosed with a CVSS score of 7.3; users are advised to include it in their patching plans, but no PoC, exploit code, or active exploitation details are provided.

    0000031
    97 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    New vulnerability disclosed: CVE-2026-26192 with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Worth reviewing if this affects your stack. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    A new vulnerability, CVE-2026-26192, with a CVSS score of 7.3 has been disclosed, affecting Open WebUI, and additional information is available at the referenced link.

    0000046
    98 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    Security advisory: CVE-2026-26192 with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Check if you need to take action. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    An advisory for CVE-2026-26192 is issued, noting its CVSS 7.3 score, with a link for further details.

    0000041
    99 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    New vulnerability disclosed: CVE-2026-26192 with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Worth reviewing if this affects your stack. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    The passage announces the disclosure of CVE-2026-26192 with a CVSS score of 7.3, but does not provide any PoC, exploit code, active exploitation evidence, or patch details.

    0000051
    97 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    Security advisory: CVE-2026-26192 with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Check if you need to take action. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    An advisory notes that CVE‑2026‑26192, with a CVSS score of 7.3, affects Open WebUI, and directs readers to a link for further details.

    0000038
    98 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    Security advisory: CVE-2026-26192 with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Check if you need to take action. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    The advisory announces CVE-2026-26192, a 7.3‑scored vulnerability affecting Open WebUI, and directs readers to check if mitigation is required, but it does not provide PoC, exploit code, or patch information.

    0000035
    95 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    New vulnerability disclosed: CVE-2026-26192 with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Worth reviewing if this affects your stack. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    The post announces CVE-2026-26192 with a CVSS score of 7.3, urging readers to review its potential impact, but it offers no exploit details, patches, or evidence of active exploitation.

    0000045
    91 followersView on X
  • Prateek Tomar@TomarPrateek23
    Patch

    CVE-2026-26192 has been published with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Add it to your patching queue if applicable. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    A brief advisory noting CVE-2026-26192 has a CVSS score of 7.3 and should be included in the patch queue.

    0000045
    91 followersView on X
  • Prateek Tomar@TomarPrateek23
    Disclosure

    Security advisory: CVE-2026-26192 with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Check if you need to take action. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    The advisory announces CVE‑2026‑26192, a CVSS‑7.3 vulnerability in Open WebUI, and urges users to review and act if affected.

    0000039
    91 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenwebuiopen_webui---

Explore more