CVE-2026-70490 | Open WebUI up to 0.10.x Terminal WebSocket Route terminals.py privileges management

SecurityVulns

A vulnerability, which was classified as critical, has been found in Open WebUI up to 0.10.x. Affected is an unknown function of the file backend/open_webui/routers/terminals.py of the component Terminal WebSocket Route. The manipulation leads to improper privilege management.

This vulnerability is uniquely identified as CVE-2026-70490. The attack is possible to be carried out remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More