CVE-2026-70494 | Open WebUI up to 0.10.x Folder folders.py improper authorization
A vulnerability, which was classified as problematic, was found in Open WebUI up to 0.10.x. Affected by this vulnerability is an unknown functionality of the file backend/open_webui/routers/folders.py of the component Folder. The manipulation results in improper authorization.
This vulnerability was named CVE-2026-70494. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More