CVE Explorer
CVE-2026-54012
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can create, update, or import workspace models store arbitrary meta.knowledge entries on their model without checking whether they own or can read the referenced files. Open WebUI then treats meta.knowledge entries of type file as an authorization source in two places: the built-in view_file tool reads the file's extracted text, and has_access_to_file()'s
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:202f6be8af0336132027cf52ba25b47895d1e8b1503276ce04c0f8554c46e9f1 · sha256:5792326f9dc3f49c… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-285","description":"CWE-285: Improper Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:202f6be8af0336132027cf52ba25b47895d1e8b1503276ce04c0f8554c46e9f1 · sha256:5792326f9dc3f49c… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:202f6be8af0336132027cf52ba25b47895d1e8b1503276ce04c0f8554c46e9f1 · sha256:5792326f9dc3f49c… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"open-webui","vendor":"open-webui","versions":[{"status":"affected","version":"< 0.9.6"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:202f6be8af0336132027cf52ba25b47895d1e8b1503276ce04c0f8554c46e9f1 · sha256:5792326f9dc3f49c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:202f6be8af0336132027cf52ba25b47895d1e8b1503276ce04c0f8554c46e9f1 · sha256:5792326f9dc3f49c… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
3 source assertions{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:202f6be8af0336132027cf52ba25b47895d1e8b1503276ce04c0f8554c46e9f1 · sha256:5792326f9dc3f49c… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-285","description":"CWE-285: Improper Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:202f6be8af0336132027cf52ba25b47895d1e8b1503276ce04c0f8554c46e9f1 · sha256:5792326f9dc3f49c… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:202f6be8af0336132027cf52ba25b47895d1e8b1503276ce04c0f8554c46e9f1 · sha256:5792326f9dc3f49c… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/open-webui/open-webui/security/advisories/GHSA-vjqm-6gcc-62cr","tags":["x_refsource_CONFIRM"],"url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-vjqm-6gcc-62cr"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:202f6be8af0336132027cf52ba25b47895d1e8b1503276ce04c0f8554c46e9f1 · sha256:5792326f9dc3f49c… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-vjqm-6gcc-62cr"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:202f6be8af0336132027cf52ba25b47895d1e8b1503276ce04c0f8554c46e9f1 · sha256:5792326f9dc3f49c… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.