CVE-2026-70487: Open WebUI: IDOR leaks other users' RAG file content

GHSA-6xhv-rxhv-pwm4 MEDIUM
Published August 4, 2026
CISO Take

Open WebUI let a chat request define an AI model inline instead of using a saved workspace model, and the knowledge files attached to that inline definition were handed to the built-in knowledge tools without checking whether the requesting user could actually read them. Any authenticated user, no admin rights needed, could pull the indexed content of another user's or group's file simply by supplying its UUID inside an inline model payload. The blast radius is bounded by the fact that file ids are UUIDs and not enumerable through this path, and EPSS sits at just the 83rd percentile with no public exploit or Nuclei template, so this reads as opportunistic insider-risk rather than an internet-wide smash-and-grab. Multi-tenant or shared-workspace Open WebUI deployments where users legitimately see each other's file ids (via links, logs, or prior collaboration) are the real exposure. Patch to 0.11.0 (fix commit 305880f2e), which filters an inline model's attached knowledge against the caller's real read access before it's used — no configuration change is required, and disabling native function calling (`function_calling: legacy`) or the model's `builtin_tools` capability is the only viable stopgap short of upgrading.

Sources: NVD GitHub Advisory EPSS ATLAS

What is the risk?

Medium risk overall (CVSS 5.3, confidentiality-only impact, no integrity/availability loss). Exploitability is constrained by a real precondition: the attacker must already know the target file's UUID, which is not enumerable or discoverable through this vulnerability itself, so this is not a scan-and-exploit bug — it requires either insider knowledge, a leaked/shared file id, or a companion information-disclosure vector. Low EPSS (0.0025, 83rd percentile) and absence from CISA KEV, plus a TRACK-only SSVC decision, confirm this is not being actively exploited and is not an urgent internet-facing threat. Risk concentrates in multi-tenant Open WebUI deployments (enterprise or team instances with many named users and shared file references) rather than single-user or air-gapped installs.

How does the attack unfold?

Reconnaissance
Attacker, already an authenticated user of the Open WebUI instance, obtains another user's file UUID through a leaked link, shared chat, or prior interaction.
Exploitation
Attacker sends a chat completion request with a client-supplied inline model definition that attaches the victim's file UUID as knowledge, using default native function calling.
AML.T0053
Impact
The built-in knowledge tool retrieves and returns the file's indexed chunks in the chat response, without ever validating the attacker's read access, leaking the victim's data.
AML.T0085.000

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Open WebUI pip >= 0.8.8, <= 0.10.2 0.11.0
153.3K 3 dependents Pushed 6d ago 83% patched ~5d to patch Full package profile →

Do you use Open WebUI? You're affected.

How severe is it?

CVSS 3.1
5.3 / 10
EPSS
0.4%
chance of exploitation in 30 days
Higher than 34% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Moderate

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC High
PR Low
UI None
S Unchanged
C High
I None
A None

What should I do?

1 step
  1. 1) Upgrade to Open WebUI 0.11.0 or later — the fix is a straightforward access-control patch with no config changes needed. 2) Until patched, reduce exposure by setting function_calling: legacy on models to disable native function calling (a stated precondition for the bug) or disabling the builtin_tools capability where feasible, though both degrade functionality. 3) Audit file/knowledge sharing practices — treat file UUIDs as sensitive if they've been shared in URLs, logs, or chat exports, since this bug turns a leaked file id into a read primitive. 4) Post-patch, review Open WebUI access logs for chat requests carrying inline model definitions with knowledge/file references during the 0.8.8–0.10.2 exposure window as a compromise-scoping exercise if the instance had multiple untrusted users.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Auth Bypass Data Leakage Privacy Violation RAG Plugin AML.T0036 AML.T0085.000

Which compliance frameworks are affected?

This CVE is relevant to:

ISO 42001
A.7 (Data for AI systems) - Data management and access control for AI system resources
OWASP LLM Top 10
LLM02:2025 - Sensitive Information Disclosure

Frequently Asked Questions

What is CVE-2026-70487?

Open WebUI let a chat request define an AI model inline instead of using a saved workspace model, and the knowledge files attached to that inline definition were handed to the built-in knowledge tools without checking whether the requesting user could actually read them. Any authenticated user, no admin rights needed, could pull the indexed content of another user's or group's file simply by supplying its UUID inside an inline model payload. The blast radius is bounded by the fact that file ids are UUIDs and not enumerable through this path, and EPSS sits at just the 83rd percentile with no public exploit or Nuclei template, so this reads as opportunistic insider-risk rather than an internet-wide smash-and-grab. Multi-tenant or shared-workspace Open WebUI deployments where users legitimately see each other's file ids (via links, logs, or prior collaboration) are the real exposure. Patch to 0.11.0 (fix commit 305880f2e), which filters an inline model's attached knowledge against the caller's real read access before it's used — no configuration change is required, and disabling native function calling (`function_calling: legacy`) or the model's `builtin_tools` capability is the only viable stopgap short of upgrading.

Is CVE-2026-70487 actively exploited?

No confirmed active exploitation of CVE-2026-70487 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-70487?

1) Upgrade to Open WebUI 0.11.0 or later — the fix is a straightforward access-control patch with no config changes needed. 2) Until patched, reduce exposure by setting `function_calling: legacy` on models to disable native function calling (a stated precondition for the bug) or disabling the `builtin_tools` capability where feasible, though both degrade functionality. 3) Audit file/knowledge sharing practices — treat file UUIDs as sensitive if they've been shared in URLs, logs, or chat exports, since this bug turns a leaked file id into a read primitive. 4) Post-patch, review Open WebUI access logs for chat requests carrying inline model definitions with `knowledge`/file references during the 0.8.8–0.10.2 exposure window as a compromise-scoping exercise if the instance had multiple untrusted users.

What systems are affected by CVE-2026-70487?

This vulnerability affects the following AI/ML architecture patterns: RAG pipelines, knowledge base / document retrieval, chat UI / model serving front-ends, multi-tenant AI assistant deployments.

What is the CVSS score for CVE-2026-70487?

CVE-2026-70487 has a CVSS v3.1 base score of 5.3 (MEDIUM). The EPSS exploitation probability is 0.42%.

What is the AI security impact?

Affected AI Architectures

RAG pipelinesknowledge base / document retrievalchat UI / model serving front-endsmulti-tenant AI assistant deployments

MITRE ATLAS Techniques

AML.T0036 Data from Information Repositories
AML.T0085.000 RAG Databases

Compliance Controls Affected

ISO 42001: A.7 (Data for AI systems)
OWASP LLM Top 10: LLM02:2025

What are the technical details?

Original Advisory

## Summary Open WebUI lets a client define a model inline on a chat request instead of selecting a saved workspace model. The knowledge attached to such an inline model was used as-is, without checking that the caller can read what it points at. Any authenticated user who knows another user's file id could therefore have the builtin knowledge tools return that file's indexed content back to them. ## Preconditions Authenticated user of any role, no admin rights needed. The request must carry a session id and use native function calling, which is the default (only `function_calling: legacy` opts out), and the model's `builtin_tools` capability must not be disabled (default enabled). The attacker must already know the target file's id; ids are UUIDs and are not enumerable through this path. No admin setting needs to be turned on: enabling Direct Connections is not required for the backend to accept an inline model. Knowledge bases attached this way were never affected, their own access grants were enforced on every path. ## Impact An authenticated user could read the indexed chunks of another user's or group's file, a cross-user confidentiality loss limited to files whose ids the attacker already holds. It is read-only: nothing is modified or deleted, knowledge-base permissions are unaffected, and saved workspace models were already validated at creation time. ## Fix Fixed in 0.11.0 by commit 305880f2e. An inline model's attached knowledge is filtered against the caller's real read access before it is used, dropping any file, knowledge base or note the caller cannot read. Upgrading fully resolves it, no configuration change is required. ## Root cause Affected component: the chat completion, chat completed and chat action endpoints, which accept an inline model definition, and the builtin knowledge tools that consume the model's attached knowledge. Affected setups: all builds from 0.8.8 through 0.10.2. Saved workspace models have their attached file references validated against the author when the model is created, updated or imported, so a stored model can only carry files its creator can read. An inline model never passes through that path, yet everything downstream treated its attached knowledge with the same trust, including a helper that grants read access to a file purely because the running model claims it as attached knowledge. The missing control was an access check at the point where client-supplied model metadata enters the request. ## Credits Reported by @whyiug.

Exploitation Scenario

An organization runs a shared Open WebUI instance for its analyst team, each with individual accounts but common visibility into some file ids (e.g., surfaced in a Slack link, a support ticket, or a previous group chat session). A curious or malicious analyst who has seen a colleague's file id — perhaps a compensation spreadsheet or an incident report uploaded to their private knowledge — crafts a raw API request to the chat completion endpoint with an inline model definition pointing its attached knowledge at that file UUID, using the default native function-calling mode. The built-in knowledge tool retrieves and returns the indexed chunks of that file directly in the chat response, without ever checking that the requester has read access, silently exfiltrating the colleague's data with no admin involvement or audit trail distinct from a normal chat query.

Weaknesses (CWE)

CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

  • [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
  • [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Timeline

Published
August 4, 2026
Last Modified
August 5, 2026
First Seen
August 5, 2026

Related Vulnerabilities