MEDIUM 4.3 GitHub

CVE-2026-70488

Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

## Summary A user with write access to one knowledge base could delete directories, and drop file embeddings, belonging to knowledge bases they do not control. The sync cleanup endpoint verified write access on the knowledge base named in the URL and then acted on the directory and file ids supplied in the request body without checking that those objects belonged to that knowledge base. ## Preconditions Default configuration, no flags involved. The attacker needs write access to at least one kn

Affected Products

References

Published: 2026-08-04 · Source: GitHub · Feed updated: 2026-08-04
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-08-04 via GitHub. Affected: pip/open-webui >= 0.9.6, <= 0.10.2.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.