CVE-2026-54010: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id values to their own...
Added to the CISA Known Exploited Vulnerabilities catalog on 23 Jun 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 8.3.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id values to their own chat message without checking whether they own or can read those files. If the attacker then shares...
Required action: Review and patch if applicable to your AI infrastructure.