CVE-2026-87994
Undergoing Analysis Undergoing Analysis - In Progress

Message Alteration via Chat Completion in Open WebUI

Vulnerability report for CVE-2026-87994, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: GitHub, Inc.

Description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, the channel branch of chat_completion in backend/open_webui/main.py checked channel write access and channel membership for a supplied message_id but did not verify that the calling user authored the targeted message. A channel member could use the chat completions endpoint to replace another member's message while preserving the victim as the stored author, altering the conversation record without gaining access to other channels. This issue is fixed in version 0.11.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open_webui open_webui From 0.9.5 (inc) to 0.11.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Open WebUI versions 0.9.5 to 0.11.1. It involves the chat completions endpoint not verifying if a user authored a message before allowing modifications. A channel member could replace another member's message while keeping the original author's name, altering conversation records without needing access to other channels.

Detection Guidance

This vulnerability affects Open WebUI versions 0.9.5 to 0.11.0. To detect it, check your Open WebUI version by running: docker inspect open-webui | grep -i version or cat /path/to/open-webui/version.txt. If the version is between 0.9.5 and 0.11.0, the system is vulnerable.

Impact Analysis

If you use Open WebUI in this version range, an attacker with channel membership could alter your messages in shared conversations, making it appear you said something you didn't. This could damage your reputation or spread misinformation while you remain falsely credited as the author.

Compliance Impact

The vulnerability allows unauthorized alteration of message authorship in chat records, which could compromise data integrity and audit trails. This may impact compliance with GDPR (data accuracy, integrity) and HIPAA (audit log integrity) by enabling undetected tampering of records.

Mitigation Strategies

Upgrade Open WebUI to version 0.11.1 or later to address the vulnerability. Review chat completion logs for unauthorized message modifications and restrict access to the chat completions endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87994. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart