CVE-2026-87012 | open-webui Open WebUI up to 0.11.0 Calendar calendar.py alert_minutes logic error

SecurityVulns

A vulnerability was found in open-webui Open WebUI up to 0.11.0. It has been declared as problematic. Impacted is an unknown function of the file backend/open_webui/models/calendar.py of the component Calendar. Executing a manipulation of the argument alert_minutes can lead to business logic errors.

This vulnerability is registered as CVE-2026-87012. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More