CVE-2026-87997: Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

Published Sep 9, 2026
·
Updated

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /api/v1/chat/completions in backend/openwebui/main.py copied a client-supplied folderid into a new chat without applying the folder write-access check used by the dedicated chat routes. An authenticated user who knew a shared folder identifier could inject an attacker-controlled chat into a folder where the user had read-only or no write access, causing the entry to appear to authorized folder readers. This issue is fixed in version 0.11.1.

Affected Software

1 affected component
Open WebUI Open WebUI>0.10.0<=0.11.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Open WebUI to a version that resolves this vulnerability.

    Fixed in 0.11.1

Event History

Sep 9, 2026
CVE Published
via MITRE·09:30 PM
Data Sourced
via MITRE·09:30 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

Open WebUI versions from 0.10.0 through 0.11.1 are identified as affected. The issue applies to deployments where users can authenticate and shared folder identifiers may be known to other users.

2

What does an attacker need to exploit this issue?

An attacker needs a valid authenticated account and the identifier of a shared folder. They can then submit a chat-completions request with that folder_id, even if they lack write permission for the folder.

3

What is the impact of successful exploitation?

An attacker can create an attacker-controlled chat in another user's shared folder. The injected chat can appear to users authorized to read that folder, while the vulnerability does not provide confidentiality or availability impact according to the supplied severity vector.

4

How can this be remediated?

Upgrade Open WebUI to version 0.11.1, which fixes the missing folder write-access check for the affected chat-completions endpoints.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203