CVE-2026-26193Disclosure(openwebui / open_webui)

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch openwebui open_webui systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.44, aanually modifying chat history allows setting the `embeds` property on a response message, the content of which is loaded into an iFrame with a sandbox that has `allow-scripts` and `allow-same-origin` set, ignoring the "iframe Sandbox Allow Same Origin" configuration. This enables stored XSS on the affected chat. This also triggers when the chat is in the shared format. The result is a shareable link containing the payload that can be distributed to any other users on the instance. Version 0.6.44 fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open_webui

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-03-08); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
open_webui

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-03-08: 1Mentions · 2026-03-15: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-18: 1PoC Mentioned / Linked · 2026-03-16: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 103-0803-1503-1603-1703-18
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-081
General1
2026-03-151
Disclosure1
2026-03-161
Disclosure1
2026-03-171
Disclosure1
2026-03-181
Patch1
Full discourse5 posts
  • Prateek Tomar@Prateektomar
    Patch

    CVE-2026-26193 has been published with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Add it to your patching queue if applicable. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    The post announces CVE‑2026‑26193, lists its 7.3 CVSS score, urges adding it to patch queues, and links to a threat‑operations page for further details.

    0001039
    97 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    New vulnerability disclosed: CVE-2026-26193 with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Worth reviewing if this affects your stack. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    The text announces the exposure of CVE-2026-26193 with a CVSS score of 7.3 and encourages users to review its relevance, but no PoC, exploit, or patch information is provided.

    0000052
    98 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    New vulnerability disclosed: CVE-2026-26193 with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Worth reviewing if this affects your stack. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    A new vulnerability, CVE-2026-26193, has been disclosed for Open WebUI with a CVSS score of 7.3, and a link to additional details is provided.

    0000047
    99 followersView on X
  • Prateek Tomar@Prateektomar
    Disclosure

    Security advisory: CVE-2026-26193 with a CVSS score of 7.3. Open WebUI is a self-hosted artificial intelligence.... Check if you need to take action. Details: https://threatops.tech/exploit-radar #CVE #InfoSec #VulnMgmt

    Post summary

    The text announces CVE-2026-26193 with a CVSS score of 7.3, refers to Open WebUI, and links to an external page for more details, but offers no proof of exploitation, remediation, or technical specifics.

    0000054
    97 followersView on X
  • Prateek Tomar@TomarPrateek23
    General

    Just published: Critical Analysis CVE-2026-26193 - Open WebUI is a self-hosted artificial.... Practical security guidance from the trenches. Read more: https://threatops.tech/blog/critical-analysis-cve-2026-26193-open-webui-is-a-self-hosted-artificial-intelligence-platform-march

    Post summary

    The text announces a blog post about CVE-2026-26193 but does not provide evidence of PoC, exploit availability, active exploitation, patches, or detailed technical information.

    0000039
    91 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenwebuiopen_webui---

Explore more