PT-2026-56830 · Unknown · Open-Webui
CVE-2026-59226
·
Published
2026-07-09
·
Updated
2026-08-04
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Open WebUI versions 0.9.0 through 0.9.x
Description
The
execute automation function rehydrated automation owners without verifying if they remained active or retained features.automations permissions. Additionally, the check model access function only enforced private-model grants for the specific user role, which allowed deactivated pending users to maintain the ability to perform scheduled model execution.Recommendations
Update to version 0.10.0.
Exploit
Fix
DoS
Improper Authorization
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open-Webui