CVE-2026-70488 | Open-WebUI Open WebUI up to 0.10.x Sync Cleanup Endpoint improper authorization

SecurityVulns

A vulnerability was found in Open-WebUI Open WebUI up to 0.10.x. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Sync Cleanup Endpoint. Such manipulation leads to improper authorization.

This vulnerability is listed as CVE-2026-70488. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More