CVE-2026-87998: Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion

Published Sep 9, 2026
·
Updated

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/openwebui/routers/knowledge.py authorized deletion against the knowledge base but then removed its administrator-owned external connection without a separate administrator check or a check for other dependent knowledge bases. A non-administrator with write access to one external knowledge base could delete shared instance configuration and make every other knowledge base using that connection unavailable. This issue is fixed in version 0.11.1.

Affected Software

1 affected component
Open WebUI Open WebUI>=0.10.0<0.11.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Open WebUI to a version that resolves this vulnerability.

    Fixed in 0.11.1

Event History

Sep 9, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A non-administrator must have write access to an external knowledge base that uses a shared administrator-owned external connection. They can trigger the affected deletion endpoint without needing administrator privileges or user interaction.

2

What is the practical impact in a shared deployment?

Deleting one writable knowledge base can remove the shared external connection configuration. Other knowledge bases that depend on that connection can become unavailable.

3

Are all Open WebUI deployments affected by default?

The issue affects versions from 0.10.0 through 0.11.1 where non-administrators have write access to an external knowledge base using an administrator-owned shared connection. Deployments without that access arrangement are not exposed through the described attack path.

4

What can be done before upgrading?

Restrict non-administrator write access to external knowledge bases that use shared administrator-owned connections. This prevents the described users from invoking deletion against a knowledge base tied to shared configuration.

5

How can administrators assess whether they may be affected?

Identify external knowledge bases writable by non-administrators and determine whether they use administrator-owned external connections shared by other knowledge bases. Those shared dependencies are the configurations at risk of being removed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203