CVE-2026-70483
Low
No strong exploitation signal.
CVSS base
3.1
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
EPSS — probability of exploitation (30 days)
0.2%
16.0th percentile
CISA KEV
Not listed
Weakness / dates
CWE-862
Published 2026-08-04 · modified 2026-09-18
CVSS breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
| Attack Vector | N | Network |
| Attack Complexity | H | High |
| Privileges Required | L | Low |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | N | None |
| Integrity | N | None |
| Availability | L | Low |
Timeline
- 2026-08-04 — Published (NVD)
- 2026-09-18 — Last modified (NVD)
Description
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether the caller could delete that chat. Any authenticated user who knew another user's chat id could abort that user's running model response, title generation, or tag generation, even though the delete was refused and no chat data was deleted, modified, or disclosed. This issue is fixed in 0.11.0.
Affected
References
- https://github.com/open-webui/open-webui/commit/4f93c3e36c1734342a32c312bdb0516c66d8e93c
- https://github.com/open-webui/open-webui/pull/27006
- https://github.com/open-webui/open-webui/releases/tag/v0.11.0
- exploit https://github.com/open-webui/open-webui/security/advisories/GHSA-3vf6-64vr-3g56
- exploit https://github.com/open-webui/open-webui/security/advisories/GHSA-3vf6-64vr-3g56