CVE-2026-28788: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, any authenticated user can overwrite any file's content by ID through the ...

Added to the CISA Known Exploited Vulnerabilities catalog on 27 Mar 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 7.1.

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, any authenticated user can overwrite any file's content by ID through the `POST /api/v1/retrieval/process/files/batch` endpoint. The endpoint performs no ownership check, so ...

Required action: Review and patch if applicable to your AI infrastructure.