Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59226

Опубликовано: 09 июл. 2026
Источник: nvd
CVSS3: 3.1
CVSS3: 4.3
EPSS Низкий

Описание

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking that they were still active or still had features.automations, and check_model_access only enforced private-model grants for the exact user role, allowing deactivated pending users to continue scheduled model execution. This issue is fixed in version 0.10.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*
Версия от 0.9.0 (включая) до 0.10.0 (исключая)

EPSS

Процентиль: 22%
0.00303
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 3.1
github
около 1 месяца назад

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

EPSS

Процентиль: 22%
0.00303
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-285