CVE-2026-70494Disclosure(openwebui / open_webui)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat folder to permanently delete chats and messages belonging to the folder owner. The cascade following the authorization check is bound to the folder owner's id, but the subfolder check accepted any inherited write grant instead of requiring ownership or administrator status. A collaborator can destroy the owner's subtree or force-move chats out of it when delete_contents=false. This issue is fixed in 0.11.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open_webui

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
open_webui

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-05: 2Technical Details · 2026-08-05: 208-05
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-70494 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/ope… https://www.cve.org/CVERecord?id=CVE-2026-70494 ----- Traducción: CVE-2026-70494 Ope… http://infoflow.cloud`

    Post summary

    The post references CVE-2026-70494, noting a delete‑folder endpoint issue in Open WebUI’s backend, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0001050
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-70494 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/ope… https://www.cve.org/CVERecord?id=CVE-2026-70494

    Post summary

    Open WebUI versions 0.10.0 through 0.11.0 are affected by CVE-2026-70494, a flaw in the DELETE /api/v1/folders/{id} endpoint; the CVE record is available but no PoC, exploit, patch, or exploitation details are provided.

    10000571
    57.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenwebuiopen_webui---

Explore more