
🟧 [New] CVE-2026-59715 | Openwebui Open Webui, CVSS: 6.5 (High) unauthorized people can interact with certain parts of the system that should be restricted to verified users a missing identity check on the tools used for collaborative documents. this allowed outsiders to influence collaborative sessions without logging in fixed in version 0.10.0, everyone should update to this version to ensure all connections are properly verified https://github.com/open-webui/open-webui/commit/22f2fe1ffb66c993dad1e0b2b35514acaed2370e
Post summary
A missing identity check in OpenWebui permits unauthorized interaction with collaborative sessions; CVE‑2026‑59715, rated CVSS 6.5, is newly disclosed and fixed in version 0.10.0.
