CVE-2026-87994 | Open WebUI up to 0.11.0 Channel Membership main.py chat_completion authorization

SecurityVulns

A vulnerability, which was classified as problematic, was found in Open WebUI up to 0.11.0. This issue affects the function chat_completion of the file backend/open_webui/main.py of the component Channel Membership. Such manipulation leads to missing authorization.

This vulnerability is referenced as CVE-2026-87994. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.VulDB Recent EntriesRead More