CVE-2026-54006: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST /api/v1/calendars/events/{event_id}/update validates that the caller has writ...

Added to the CISA Known Exploited Vulnerabilities catalog on 23 Jun 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 4.3.

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST /api/v1/calendars/events/{event_id}/update validates that the caller has write access to the calendar the event currently belongs to, but does not validate the destination calen...

Required action: Review and patch if applicable to your AI infrastructure.