PT-2026-1997 · Openwebui+1 · Open-Webui

Brandon Niemczyk

+2

·

Published

2026-01-09

·

Updated

2026-01-23

·

CVE-2026-0767

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI (affected versions not specified)
Description A flaw exists in Open WebUI that allows network-adjacent attackers to disclose sensitive information. The issue stems from transmitting credentials in plaintext through an unspecified endpoint. Authentication is not required for exploitation. Successful exploitation could lead to further compromise of the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2026-0767
ZDI-26-033

Affected Products

Open-Webui