← Back to CVE search

CVE-2026-70494

Description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat folder to permanently delete chats and messages belonging to the folder owner. The cascade following the authorization check is bound to the folder owner-s id, but the subfolder check accepted any inherited write grant instead of requiring ownership or administrator status. A collaborator can destroy the owner-s subtree or force-move chats out of it when delete_contents=false. This issue is fixed in 0.11.0.

CVSS 8.1EPSS 0.297%Risk 0.83
View source
Published
2026-08-04 21:16:38
Last modified
2026-08-05 15:17:12
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H