PT-2026-1997 · Openwebui+1 · Open-Webui

·

CVE-2026-0767

·

Published

2026-01-09

·

Updated

2026-01-23

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI (affected versions not specified)
Description A flaw exists in Open WebUI that allows network-adjacent attackers to disclose sensitive information. The issue stems from transmitting credentials in plaintext through an unspecified endpoint. Authentication is not required for exploitation. Successful exploitation could lead to further compromise of the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-0767
ZDI-26-033

Affected Products

Open-Webui