CVE-2026-87017
Undergoing Analysis Undergoing Analysis - In Progress

Information Disclosure in Open WebUI Knowledge Search

Vulnerability report for CVE-2026-87017, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: GitHub, Inc.

Description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.1, the built-in knowledge search tool passed the caller's readable knowledge identifiers through a metadata filter, but the search methods in eleven shipped vector backends ignored that filter. An authenticated user on an affected backend could enumerate the identifiers, names, and descriptions of inaccessible knowledge bases from the shared collection, although the associated document text remained in separate collections. This issue is fixed in version 0.11.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open_webui open_webui From 0.7.0 (inc) to 0.11.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Open WebUI (versions 0.7.0 to 0.11.1) involves an improper metadata filter in the knowledge search tool. Authenticated users could access names and descriptions of restricted knowledge bases through certain vector backends, even though they lacked permission to view the actual content.

Detection Guidance

This vulnerability affects Open WebUI versions 0.7.0 to 0.11.1. To detect it, check your Open WebUI version with: docker inspect open-webui | grep -i version or open-webui --version. If your version is between 0.7.0 and 0.11.1, the system is vulnerable. Additionally, review logs for unauthorized access attempts to knowledge base metadata.

Impact Analysis

An attacker with access could learn about sensitive knowledge bases they shouldn't see, potentially exposing metadata about restricted information. This could lead to further attacks or data leaks if combined with other vulnerabilities.

Compliance Impact

This vulnerability allows authenticated users to enumerate metadata of inaccessible knowledge bases, which could potentially expose sensitive information about restricted data sources. This may impact compliance with GDPR by risking unauthorized access to personal data identifiers or HIPAA by revealing details about protected health information systems.

Mitigation Strategies

Upgrade Open WebUI to version 0.11.1 or later to address the vulnerability in the knowledge search tool and vector backends.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87017. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart