CVE-2026-87997 | Open WebUI up to 0.11.0 Folder Write Access Check main.py folder_id improper authorization

SecurityVulns

A vulnerability labeled as problematic has been found in Open WebUI up to 0.11.0. Affected by this issue is some unknown functionality of the file backend/open_webui/main.py of the component Folder Write Access Check. Executing a manipulation of the argument folder_id can lead to improper authorization.

This vulnerability appears as CVE-2026-87997. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More