PT-2026-1997 · Openwebui+1 · Open-Webui

Brandon Niemczyk

+2

·

Publicado

2026-01-09

·

Atualizado

2026-01-23

·

CVE-2026-0767

CVSS v3.1

6.5

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI (affected versions not specified)
Description A flaw exists in Open WebUI that allows network-adjacent attackers to disclose sensitive information. The issue stems from transmitting credentials in plaintext through an unspecified endpoint. Authentication is not required for exploitation. Successful exploitation could lead to further compromise of the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-0767
ZDI-26-033

Produtos afetados

Open-Webui