CVE-2026-87998 | Open WebUI up to 0.11.0 Knowledge Base knowledge.py improper authorization

SecurityVulns

A vulnerability marked as problematic has been reported in Open WebUI up to 0.11.0. This affects an unknown part of the file backend/open_webui/routers/knowledge.py of the component Knowledge Base. The manipulation leads to improper authorization.

This vulnerability is traded as CVE-2026-87998. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More