Incorrect Authorization Affecting open-webui package, versions [0.7.0,0.11.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.37% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-OPENWEBUI-20158696
  • published27 Sept 2026
  • disclosed10 Sept 2026
  • creditUnknown

Introduced: 10 Sep 2026

NewCVE-2026-87017  (opens in a new tab)
CWE-200  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade open-webui to version 0.11.1 or higher.

Overview

open-webui is an Open WebUI

Affected versions of this package are vulnerable to Incorrect Authorization in the search process. An attacker can obtain unauthorized access to the identifier, name, and description of knowledge bases by exploiting improper filter application in certain vector backends. This is only exploitable if the deployment uses one of the affected vector backends (excluding Chroma, pgvector, MariaDB, or Valkey), the caller has access to a model with the knowledge tool enabled and no knowledge attached, and at least one knowledge base exists that the caller cannot otherwise read.

CVSS Base Scores

version 4.0
version 3.1