CVE-2026-87999: Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch

Published Sep 9, 2026
·
Updated

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.1, POST /api/v1/retrieval/process/web and POST /api/v1/retrieval/process/web/search in backend/openwebui/retrieval/web/utils.py treated Python's globally routable address classification as proof that a destination was external. An authenticated user could make an Azure-hosted instance fetch and return content from 168.63.129.16, the Azure platform channel, as well as other reserved ranges that the standard classification did not reject. This issue is fixed in version 0.11.1.

Affected Software

1 affected component
Open WebUI Open WebUI<0.11.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Open WebUI to a version that resolves this vulnerability.

    Fixed in 0.11.1
  2. Configuration

    Upgrade to 0.11.1 to fix POST /api/v1/retrieval/process/web and POST /api/v1/retrieval/process/web/search so they no longer treat Python's globally routable address classification as proof that a destination is external.

    Open WebUI (backend/open_webui/retrieval/web/utils.py) Web fetch destination classification = Use proper destination validation instead of Python's globally routable address classification as proof the destination is external

Event History

Sep 9, 2026
CVE Published
via MITRE·09:33 PM
Data Sourced
via MITRE·09:33 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated Open WebUI user can exploit it. No user interaction is required, but exploitation requires access to the affected web retrieval endpoints.

2

Which deployments are most exposed?

Azure-hosted Open WebUI instances are specifically exposed because an attacker can cause the server to fetch content from the Azure platform channel at 168.63.129.16. Other reserved address ranges that were not rejected by the address classification may also be reachable.

3

What versions are affected and what is the fix?

Open WebUI versions prior to 0.11.1 are affected. Upgrade to version 0.11.1, which fixes the destination validation issue in the web retrieval processing endpoints.

4

How can I determine whether my instance is affected?

An instance is affected if it runs a version earlier than 0.11.1 and exposes POST /api/v1/retrieval/process/web or POST /api/v1/retrieval/process/web/search to authenticated users. Azure-hosted instances should treat successful server-side requests to 168.63.129.16 as an indication of exposure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203