CVE-2026-59215
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handl
CVSS
3.1
Low
EPSS
0.3%
p17
KEV
—
Exploit Today
5
0-100
Published: Jul 9, 2026 · Last modified: Jul 13, 2026 · CWE-639
0.3%EPSS · 30 days0.3%
2026-07-102026-07-20
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to the channel in the URL, allowing an authenticated user to reference a message from another private or DM channel and disclose thread context across channels. This issue is fixed in version 0.10.0.
- github.comhttps://github.com/open-webui/open-webui/commit/a66477b7104c5d141ce7bffaea424b43e7666ef1
- github.comhttps://github.com/open-webui/open-webui/pull/25766
- github.comhttps://github.com/open-webui/open-webui/releases/tag/v0.10.0
- github.comhttps://github.com/open-webui/open-webui/security/advisories/GHSA-73x5-h92w-xc2j
- github.comhttps://github.com/open-webui/open-webui/security/advisories/GHSA-73x5-h92w-xc2j
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-552558.4 HIG42.9%
KEV—63Langflow Authorization Bypass Through User-Controlled Key Vulnerability13dCVE-2021-464168.1 HIG89.9%
——27Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.8dCVE-2022-289867.5 HIG80.9%
——24LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.12dCVE-2020-234465.3 MED65.5%
——20Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API12dCVE-2021-33806.5 MED61.6%
——18Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive information via the Print Invoice Functionality.12dCVE-2022-362029.8 CRI51.6%
——15Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.12d