CVE-2026-29070: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an access control check is missing when deleting a file from a knowledge b...
Added to the CISA Known Exploited Vulnerabilities catalog on 27 Mar 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 5.4.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an access control check is missing when deleting a file from a knowledge base. The only check being done is that the user has write access to the knowledge base (or is admin)...
Required action: Review and patch if applicable to your AI infrastructure.