AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-59214

HIGH · CVSS 7.3 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

Open WebUI versions prior to 0.10.0 are vulnerable due to a flaw that allows stored chat payloads to issue authenticated requests to admin-only endpoints, potentially enabling unauthorized execution of server-side code. This high-severity vulnerability poses significant risks to users who rely on this self-hosted AI platform, particularly those managing sensitive data or administrative functions. Organizations using affected versions should prioritize upgrading to version 0.10.0 to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59214
Severity
HIGH
CVSS
7.3
EPSS
0.29%

Original NVD Description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpRequest APIs to issue authenticated same-origin requests when a victim clicks Run, which can reach admin-only endpoints and execute server-side code through configured tools. This issue is fixed in version 0.10.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)