CVE-2026-70494: Open WebUI: broken authz lets collaborator delete chats

GHSA-3cg5-48j3-v4gv HIGH
Published August 4, 2026
CISO Take

A missing-ownership check in Open WebUI's folder deletion endpoint lets any user with write access to a shared folder permanently destroy the owner's chats and messages, because write grants inherited by subfolders were treated as sufficient authorization for deletion instead of requiring actual ownership. This matters for any team using Open WebUI as a shared front-end to LLMs or Ollama, since a single overshared collaborator relationship can wipe out chat history that may hold research context, prompts, or audit trails — with no way to recover it. The exploitation bar is low (a single authenticated DELETE request) but real-world exposure is narrower than the CVSS 8.1 suggests: folder sharing is off by default, EPSS sits at 0.003 (no observed exploitation), it's not in CISA KEV, and CISA's own SSVC call is TRACK, not Act. Teams running any release from 0.10.0 through 0.10.x with `user.permissions.sharing.folders` enabled should upgrade to 0.11.0 immediately, and in the interim disable folder sharing or audit who holds write access on shared folders to limit blast radius.

Sources: NVD GitHub Advisory EPSS CISA KEV ATLAS

What is the risk?

CVSS 8.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) reflects severe integrity/availability impact with no confidentiality loss — this is destructive, not disclosive. Real-world risk is meaningfully gated by preconditions: folder sharing must be explicitly enabled (off by default), the victim must have granted the attacker write access to a folder, and the attacker needs a valid low-privilege account (PR:L). No public PoC, no Nuclei template, not in CISA KEV, and EPSS is negligible (0.00297), all consistent with CISA's TRACK-only SSVC decision — this is a real bug to patch on your next maintenance window, not an active-exploitation emergency. Multi-tenant or team deployments of open-webui with sharing enabled carry the most exposure; single-user instances are unaffected.

How does the attack unfold?

Precondition abuse
Attacker holds a valid low-privilege account and is granted write access to a shared folder under the victim's folder-sharing settings.
Privilege inheritance
Write access on the shared root folder implicitly extends to every subfolder, including ones the victim never explicitly shared with the attacker.
Exploitation
Attacker sends DELETE /api/v1/folders/{id} on a subfolder; the handler checks only for write access instead of verifying ownership, so the request is authorized.
Impact
The deletion cascades into the owner's chats and the entire subfolder subtree, permanently destroying chat history (or force-relocating it if delete_contents=false).
AML.T0092

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Open WebUI pip >= 0.10.0, < 0.11.0 0.11.0
153.3K 3 dependents Pushed 6d ago 83% patched ~5d to patch Full package profile →

Do you use Open WebUI? You're affected.

How severe is it?

CVSS 3.1
8.1 / 10
EPSS
0.5%
chance of exploitation in 30 days
Higher than 44% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Trivial

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR Low
UI None
S Unchanged
C None
I High
A High

What should I do?

1 step
  1. Upgrade to open-webui 0.11.0 or later, which unifies the authorization check so only the folder owner or an admin can delete root folders or subfolders (fix in PR #27003 / commit 915ef7d). No configuration change is required post-upgrade. Until patched, disable user.permissions.sharing.folders to remove the attack surface entirely, or restrict folder-sharing write grants to trusted users only. Detection: audit logs/DB for DELETE /api/v1/folders/{id} calls where the requester is not the folder owner, and review chat/folder tables for unexpected mass deletions or relocations correlated with a non-owner actor. Since AI Package Risk Score for open-webui is already elevated (38/100, 150 other CVEs in the package), prioritize this alongside a broader patch-cadence review for the package.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
ISO 42001
Annex A.6 - Data for AI systems
NIST AI RMF
MANAGE-1.3 - Manage risks from third-party AI system components

Frequently Asked Questions

What is CVE-2026-70494?

A missing-ownership check in Open WebUI's folder deletion endpoint lets any user with write access to a shared folder permanently destroy the owner's chats and messages, because write grants inherited by subfolders were treated as sufficient authorization for deletion instead of requiring actual ownership. This matters for any team using Open WebUI as a shared front-end to LLMs or Ollama, since a single overshared collaborator relationship can wipe out chat history that may hold research context, prompts, or audit trails — with no way to recover it. The exploitation bar is low (a single authenticated DELETE request) but real-world exposure is narrower than the CVSS 8.1 suggests: folder sharing is off by default, EPSS sits at 0.003 (no observed exploitation), it's not in CISA KEV, and CISA's own SSVC call is TRACK, not Act. Teams running any release from 0.10.0 through 0.10.x with `user.permissions.sharing.folders` enabled should upgrade to 0.11.0 immediately, and in the interim disable folder sharing or audit who holds write access on shared folders to limit blast radius.

Is CVE-2026-70494 actively exploited?

No confirmed active exploitation of CVE-2026-70494 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-70494?

Upgrade to open-webui 0.11.0 or later, which unifies the authorization check so only the folder owner or an admin can delete root folders or subfolders (fix in PR #27003 / commit 915ef7d). No configuration change is required post-upgrade. Until patched, disable `user.permissions.sharing.folders` to remove the attack surface entirely, or restrict folder-sharing write grants to trusted users only. Detection: audit logs/DB for `DELETE /api/v1/folders/{id}` calls where the requester is not the folder owner, and review chat/folder tables for unexpected mass deletions or relocations correlated with a non-owner actor. Since AI Package Risk Score for open-webui is already elevated (38/100, 150 other CVEs in the package), prioritize this alongside a broader patch-cadence review for the package.

What systems are affected by CVE-2026-70494?

This vulnerability affects the following AI/ML architecture patterns: self-hosted LLM chat interfaces, collaborative AI workspaces, agent frameworks.

What is the CVSS score for CVE-2026-70494?

CVE-2026-70494 has a CVSS v3.1 base score of 8.1 (HIGH). The EPSS exploitation probability is 0.55%.

What is the AI security impact?

Affected AI Architectures

self-hosted LLM chat interfacescollaborative AI workspacesagent frameworks

MITRE ATLAS Techniques

AML.T0092 Manipulate User LLM Chat History

Compliance Controls Affected

EU AI Act: Article 15
ISO 42001: Annex A.6
NIST AI RMF: MANAGE-1.3

What are the technical details?

Original Advisory

## Summary A user granted write access to a shared chat folder could permanently delete chats and messages belonging to the folder's owner. Deleting a folder cascades into the owner's chats and the entire subfolder subtree, and the deletion handler required only write access on subfolders instead of ownership. Root folders were restricted to the owner or an admin, subfolders were not. ## Preconditions The Folders Sharing permission (`user.permissions.sharing.folders`) must be enabled; it is off by default. The victim must have shared a folder with the attacker at write access. `features.folders` and the `chat.delete` permission are enabled by default and are both required. Deployments that leave folder sharing disabled are not affected, and neither are single-user instances. ## Impact Permanent, irreversible destruction of another user's chat history within and beneath a shared folder. With `delete_contents=false` the same request instead force-moved the owner's chats out of the folder, an unauthorized relocation rather than a deletion. The write grant on the shared root folder is inherited by every descendant, so the attacker could destroy subfolders that were never explicitly shared with them. Nothing outside the shared folder's subtree is reachable, and no data is disclosed that write access did not already expose. ## Fix Fixed in 0.11.0 by https://github.com/open-webui/open-webui/pull/27003. Folder deletion is now restricted to the folder owner or an admin for root folders and subfolders alike, replacing the previous root/subfolder split with a single check. Upgrading fully resolves the issue; no configuration change is required. Owners and admins are unaffected, and a write-collaborator can still create, rename and add to shared folders and delete subfolders they own. ## Root cause Affected component: `backend/open_webui/routers/folders.py`, the `DELETE /api/v1/folders/{id}` handler. Affected setup: any release from 0.10.0 onward that has folder sharing enabled. The cascade that follows the authorization check is bound to the folder owner's id, not the caller's, so whoever passes the check deletes the owner's data. The check itself branched on whether the folder had a parent: root folders demanded ownership or admin, while subfolders accepted any write grant. Because write grants propagate down the folder tree, that branch handed every collaborator deletion rights over the owner's subtree, which is broader than what the sharing model grants write access. ## Credits @legobattman, who reported the issue and its remediation.

Exploitation Scenario

An organization enables folder sharing to let a security analyst collaborate with a teammate on an incident-response chat folder, granting the teammate write access so they can add notes. The teammate (or an account of theirs later compromised) sends a single authenticated `DELETE /api/v1/folders/{id}` request targeting a subfolder — even one containing sensitive chats the analyst never explicitly shared, since write access cascades down the tree. The handler checks only for write access on that subfolder rather than verifying ownership, so the request succeeds; the deletion cascades and permanently destroys the owner's chats, messages, and all nested subfolders, wiping incident history with no confidentiality breach and no obvious external signal that an attack occurred.

Weaknesses (CWE)

CWE-862 — Missing Authorization: The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

  • [Architecture and Design] Divide the product into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully mapping roles with data and functionality. Use role-based access control (RBAC) [REF-229] to enforce the roles at the appropriate boundaries. Note that this approach may not protect against horizontal authorization, i.e., it will not protect a user from attacking others with the same role.
  • [Architecture and Design] Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for medical records to a specific database user, but each record might only be intended to be accessible to the patient and the patient's doctor [REF-7].

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Timeline

Published
August 4, 2026
Last Modified
August 5, 2026
First Seen
August 5, 2026

Related Vulnerabilities