PT-2026-67862 · Unknown · Open-Webui
CVE-2026-70494
·
Published
2026-08-04
·
Updated
2026-08-10
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Open WebUI versions 0.10.0 through 0.10.9
Description
A flaw in the
DELETE /api/v1/folders/{id} endpoint allows a user with write access to a shared chat folder to permanently delete chats and messages belonging to the folder owner. This occurs because the authorization check for subfolders accepted any inherited write grant instead of requiring ownership or administrator status. Consequently, a collaborator can destroy the owner's subtree or force-move chats out of it when the delete contents variable is set to false. This issue requires the Folders Sharing permission (user.permissions.sharing.folders) to be enabled, as it is disabled by default. Single-user instances and deployments with folder sharing disabled are not affected.Recommendations
Update to version 0.11.0.
Exploit
Fix
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open-Webui