
CVE-2026-28786 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an unsanitized filename field in the speech… https://www.cve.org/CVERecord?id=CVE-2026-28786
Post summary
The post announces CVE‑2026‑28786 as an unsanitized file name vulnerability in Open WebUI, noting that the issue is fixed in version 0.8.6.

