SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-56398

HIGH · CVSS 7.3 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Open WebUI versions prior to 0.9.5 are vulnerable to a stored cross-site scripting flaw in the OAuth authentication flow, allowing SVG files to bypass validation and be stored as data URIs. This vulnerability enables authenticated users to inadvertently execute malicious scripts, potentially leading to the theft of authentication tokens and account takeover. Organizations using Open WebUI should prioritize patching this vulnerability to safeguard against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56398
Severity
HIGH
CVSS
7.3
EPSS
0.42%

Original NVD Description

Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover.

Related CVEs

Other vulnerabilities affecting the same vendor(s)