Open WebUI let a chat request define an AI model inline instead of using a saved workspace model, and the knowledge files attached to that inline definition were handed to the built-in knowledge tools without checking whether the requesting user could actually read them. Any authenticated user, no admin rights needed, could pull the indexed content of another user's or group's file simply by supplying its UUID inside an inline model payload. The blast radius is bounded by the fact that file ids are UUIDs and not enumerable through this path, and EPSS sits at just the 83rd percentile with no public exploit or Nuclei template, so this reads as opportunistic insider-risk rather than an internet-wide smash-and-grab. Multi-tenant or shared-workspace Open WebUI deployments where users legitimately see each other's file ids (via links, logs, or prior collaboration) are the real exposure. Patch to 0.11.0 (fix commit 305880f2e), which filters an inline model's attached knowledge against the caller's real read access before it's used — no configuration change is required, and disabling native function calling (`function_calling: legacy`) or the model's `builtin_tools` capability is the only viable stopgap short of upgrading.
What is the risk?
Medium risk overall (CVSS 5.3, confidentiality-only impact, no integrity/availability loss). Exploitability is constrained by a real precondition: the attacker must already know the target file's UUID, which is not enumerable or discoverable through this vulnerability itself, so this is not a scan-and-exploit bug — it requires either insider knowledge, a leaked/shared file id, or a companion information-disclosure vector. Low EPSS (0.0025, 83rd percentile) and absence from CISA KEV, plus a TRACK-only SSVC decision, confirm this is not being actively exploited and is not an urgent internet-facing threat. Risk concentrates in multi-tenant Open WebUI deployments (enterprise or team instances with many named users and shared file references) rather than single-user or air-gapped installs.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Open WebUI | pip | >= 0.8.8, <= 0.10.2 | 0.11.0 |
Do you use Open WebUI? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
1) Upgrade to Open WebUI 0.11.0 or later — the fix is a straightforward access-control patch with no config changes needed. 2) Until patched, reduce exposure by setting
function_calling: legacyon models to disable native function calling (a stated precondition for the bug) or disabling thebuiltin_toolscapability where feasible, though both degrade functionality. 3) Audit file/knowledge sharing practices — treat file UUIDs as sensitive if they've been shared in URLs, logs, or chat exports, since this bug turns a leaked file id into a read primitive. 4) Post-patch, review Open WebUI access logs for chat requests carrying inline model definitions withknowledge/file references during the 0.8.8–0.10.2 exposure window as a compromise-scoping exercise if the instance had multiple untrusted users.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-70487?
Open WebUI let a chat request define an AI model inline instead of using a saved workspace model, and the knowledge files attached to that inline definition were handed to the built-in knowledge tools without checking whether the requesting user could actually read them. Any authenticated user, no admin rights needed, could pull the indexed content of another user's or group's file simply by supplying its UUID inside an inline model payload. The blast radius is bounded by the fact that file ids are UUIDs and not enumerable through this path, and EPSS sits at just the 83rd percentile with no public exploit or Nuclei template, so this reads as opportunistic insider-risk rather than an internet-wide smash-and-grab. Multi-tenant or shared-workspace Open WebUI deployments where users legitimately see each other's file ids (via links, logs, or prior collaboration) are the real exposure. Patch to 0.11.0 (fix commit 305880f2e), which filters an inline model's attached knowledge against the caller's real read access before it's used — no configuration change is required, and disabling native function calling (`function_calling: legacy`) or the model's `builtin_tools` capability is the only viable stopgap short of upgrading.
Is CVE-2026-70487 actively exploited?
No confirmed active exploitation of CVE-2026-70487 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-70487?
1) Upgrade to Open WebUI 0.11.0 or later — the fix is a straightforward access-control patch with no config changes needed. 2) Until patched, reduce exposure by setting `function_calling: legacy` on models to disable native function calling (a stated precondition for the bug) or disabling the `builtin_tools` capability where feasible, though both degrade functionality. 3) Audit file/knowledge sharing practices — treat file UUIDs as sensitive if they've been shared in URLs, logs, or chat exports, since this bug turns a leaked file id into a read primitive. 4) Post-patch, review Open WebUI access logs for chat requests carrying inline model definitions with `knowledge`/file references during the 0.8.8–0.10.2 exposure window as a compromise-scoping exercise if the instance had multiple untrusted users.
What systems are affected by CVE-2026-70487?
This vulnerability affects the following AI/ML architecture patterns: RAG pipelines, knowledge base / document retrieval, chat UI / model serving front-ends, multi-tenant AI assistant deployments.
What is the CVSS score for CVE-2026-70487?
CVE-2026-70487 has a CVSS v3.1 base score of 5.3 (MEDIUM). The EPSS exploitation probability is 0.42%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0036 Data from Information Repositories AML.T0085.000 RAG Databases Compliance Controls Affected
What are the technical details?
Original Advisory
## Summary Open WebUI lets a client define a model inline on a chat request instead of selecting a saved workspace model. The knowledge attached to such an inline model was used as-is, without checking that the caller can read what it points at. Any authenticated user who knows another user's file id could therefore have the builtin knowledge tools return that file's indexed content back to them. ## Preconditions Authenticated user of any role, no admin rights needed. The request must carry a session id and use native function calling, which is the default (only `function_calling: legacy` opts out), and the model's `builtin_tools` capability must not be disabled (default enabled). The attacker must already know the target file's id; ids are UUIDs and are not enumerable through this path. No admin setting needs to be turned on: enabling Direct Connections is not required for the backend to accept an inline model. Knowledge bases attached this way were never affected, their own access grants were enforced on every path. ## Impact An authenticated user could read the indexed chunks of another user's or group's file, a cross-user confidentiality loss limited to files whose ids the attacker already holds. It is read-only: nothing is modified or deleted, knowledge-base permissions are unaffected, and saved workspace models were already validated at creation time. ## Fix Fixed in 0.11.0 by commit 305880f2e. An inline model's attached knowledge is filtered against the caller's real read access before it is used, dropping any file, knowledge base or note the caller cannot read. Upgrading fully resolves it, no configuration change is required. ## Root cause Affected component: the chat completion, chat completed and chat action endpoints, which accept an inline model definition, and the builtin knowledge tools that consume the model's attached knowledge. Affected setups: all builds from 0.8.8 through 0.10.2. Saved workspace models have their attached file references validated against the author when the model is created, updated or imported, so a stored model can only carry files its creator can read. An inline model never passes through that path, yet everything downstream treated its attached knowledge with the same trust, including a helper that grants read access to a file purely because the running model claims it as attached knowledge. The missing control was an access check at the point where client-supplied model metadata enters the request. ## Credits Reported by @whyiug.
Exploitation Scenario
An organization runs a shared Open WebUI instance for its analyst team, each with individual accounts but common visibility into some file ids (e.g., surfaced in a Slack link, a support ticket, or a previous group chat session). A curious or malicious analyst who has seen a colleague's file id — perhaps a compensation spreadsheet or an incident report uploaded to their private knowledge — crafts a raw API request to the chat completion endpoint with an inline model definition pointing its attached knowledge at that file UUID, using the default native function-calling mode. The built-in knowledge tool retrieves and returns the indexed chunks of that file directly in the chat response, without ever checking that the requester has read access, silently exfiltrating the colleague's data with no admin involvement or audit trail distinct from a normal chat query.
Weaknesses (CWE)
CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
- [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
- [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N References
Timeline
Related Vulnerabilities
CVE-2026-44551 9.1 open-webui: LDAP auth bypass — full account takeover
Same package: open-webui CVE-2026-45672 8.8 open-webui: code exec gate bypass via API endpoint
Same package: open-webui CVE-2026-44552 8.7 open-webui: Redis cache poisoning enables cross-instance tool hijack
Same package: open-webui CVE-2025-64495 8.7 Open WebUI: XSS-to-RCE via malicious prompt injection
Same package: open-webui CVE-2026-45315 8.7 open-webui: stored XSS → JWT theft and admin takeover
Same package: open-webui