CVE-2026-87998

HIGH CVSS 3.1: 7.1 EPSS 0.27%
Updated Sep 10, 2026
Open
Parameter Value
CVSS 7.1 (HIGH)
Fixed In 0.11.1
Type CWE-863 (Incorrect Authorization), CWE-269 (Improper Privilege Management)
Vendor Open
Public PoC No

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against the knowledge base but then removed its administrator-owned external connection without a separate administrator check or a check for other dependent knowledge bases. A non-administrator with write access to one external knowledge base could delete shared instance configuration and make every other knowledge base using that connection unavailable.

This issue is fixed in version 0.11.1.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
Low
Partial disruption

CVSS Vector v3.1