CVE-2026-59216
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:pyth
CVSS
7.7
Alto
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Publicado: 9 jul 2026 · Última mod.: 13 jul 2026 · CWE-94 · CWE-200 · CWE-639
0.3%EPSS · 30 días0.3%
2026-07-102026-07-21
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the session was connected, allowing authenticated users who learned another socket ID through ydoc:document:join to run code interpreter Python or tools in that user session. This issue is fixed in version 0.10.0.
- github.comhttps://github.com/open-webui/open-webui/commit/386ac958144dbbbf0aa6e268070d72b681a318aa
- github.comhttps://github.com/open-webui/open-webui/pull/25763
- github.comhttps://github.com/open-webui/open-webui/releases/tag/v0.10.0
- github.comhttps://github.com/open-webui/open-webui/security/advisories/GHSA-74h3-cxq7-vc5q
- github.comhttps://github.com/open-webui/open-webui/security/advisories/GHSA-74h3-cxq7-vc5q
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-24066.5 MED—
———Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client.
This issue affects Online Registration and Workflow Management System: through 12022026.4hCVE-2026-632624.3 MED—
——0Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.13hCVE-2026-632594.3 MED—
——0Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.14hCVE-2026-631434.3 MED—
——0Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may include sensitive information returned by workflow steps, such as results from connected data sources that the caller would not otherwise be authorized to access.14hCVE-2026-164864.3 MED—
——0A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used.14hCVE-2026-164854.3 MED—
——0A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.14h