2026-05-15
2026-05-15 20:16Z
HIGH

CVE-2026-45675 — Open: Prior to 0.9.0, he LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) pattern

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45675

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, he LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) pattern for first-user admin role assignment. The regular signup handler (signup_handler in auths.py, line 663) was explicitly patched to prevent this race with the comment "Insert with default role first to avoid TOCTOU race", but the LDAP and OAuth code paths were never updated with CVSSv3.1 8.1 (HIGH)

CWECWE 269CWECWE 362TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-15
2026-05-15 20:16Z
HIGH

CVE-2026-45671 — Open: Prior to 0.9.0, any authenticated user can permanently delete files owned by other users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45671

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user can permanently delete files owned by other users via DELETE /api/v1/files/{id} when the target file is referenced in any shared chat. The has_access_to_file() authorization gate unconditionally grants access through its shared-chat branch. It checks neither the requesting user's identity nor the type of operation being performed. File UUID CVSSv3.1 8.0 (HIGH)

CWECWE 639TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-05-15
2026-05-15 20:16Z
HIGH

CVE-2026-45331 — Open: Prior to 0.9.0, validate_url() in backend/open_webui/retrieval/web/utils.py calls validators.ipv6(ip, private=True), but the validators library does

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45331

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, validate_url() in backend/open_webui/retrieval/web/utils.py calls validators.ipv6(ip, private=True), but the validators library does NOT implement the private keyword for IPv6 — the call raises a ValidationError (which is falsy in a boolean context), so every IPv6 address passes the filter. In addition, IPv4-mapped IPv6 (::ffff:10.0.0.1) bypasses the IPv4 check e CVSSv3.1 8.5 (HIGH)

CWECWE 918TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-15
2026-05-15 20:16Z
HIGH

CVE-2026-44554 — Open: Prior to 0.9.0, the POST /api/v1/retrieval/process/web endpoint accepts a user-supplied collection_name and an overwrite

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44554

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/retrieval/process/web endpoint accepts a user-supplied collection_name and an overwrite query parameter (default: True). It performs no authorization check on whether the calling user owns or has write access to the target collection. When overwrite=True, save_docs_to_vector_db calls VECTOR_DB_CLIENT.delete_collection() on the target collection b CVSSv3.1 8.1 (HIGH)

CWECWE 862TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-15
2026-05-15 20:16Z
HIGH

CVE-2026-44553 — Open: Prior to 0.9.0, administrative role changes and user deletions do not iterate SESSION_POOL to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44553

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, administrative role changes and user deletions do not iterate SESSION_POOL to disconnect affected sessions. As a result, a user whose admin role has been revoked retains admin privileges within their existing Socket.IO session for as long as they keep the connection alive (via automatic heartbeats). The gap is exclusive to the Socket.IO session cache. This vulner CVSSv3.1 8.1 (HIGH)

CWECWE 613TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-15
2026-05-15 20:16Z
HIGH

CVE-2026-44552 — Open: Prior to 0.9.0, the tool_servers and terminal_servers keys in utils/tools.py do use a prefix.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44552

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the tool_servers and terminal_servers keys in utils/tools.py do use a prefix. When two or more Open WebUI instances share a Redis database (a supported and documented deployment pattern, e.g., for multi-region deployments, blue-green setups, or cluster topologies), the unprefixed keys collide. An admin on Instance A writing to tool_servers overwrites the value re CVSSv3.1 8.7 (HIGH)

CWECWE 668TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-15
2026-05-15 20:16Z
CRIT

CVE-2026-44551 — Open: Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44551

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is non-empty before performing a Simple Bind against the LDAP server. The LdapForm Pydantic model accepts password: str with no minimum length constraint, so an empty string passes validation. The subsequent Connection.bind() call succeeds on vulnerable LDAP servers, and the applicatio CVSSv3.1 9.1 (CRITICAL)

CWECWE 287TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-15
2026-05-15 19:17Z
HIGH

CVE-2026-46407 — Vvveb: Prior to 1.0.8.3, the backend admin/auth-token endpoint allows an authenticated administrator to load another

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46407

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-token endpoint allows an authenticated administrator to load another administrator's REST API token list by supplying that user's admin_id. This can disclose sensitive API tokens belonging to other administrators. This vulnerability is fixed in 1.0.8.3. CVSSv3.1 8.1 (HIGH)

CWECWE 639VNDVvvebTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-15
2026-05-15 19:17Z
CRIT

CVE-2026-46364 — phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46364

phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent headers into DELETE and INSERT queries. Unauthenticated attackers can exploit the public GET /api/captcha endpoint by crafting malicious User-Agent headers to perform time-based blind SQL injection, extracting sensitive data including user credentials, admin tokens, and SMTP creden CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-15
2026-05-15 19:17Z
CRIT

CVE-2026-45010 — phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45010

phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/check endpoint, which accepts arbitrary user-id parameters without session binding or rate limiting. Unauthenticated attackers can brute-force any user's six-digit TOTP code by submitting POST requests with sequential token values, bypassing two-factor authentication to gain full administrative access. CVSSv3.1 9.1 (CRITICAL)

CWECWE 307TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-15
2026-05-15 19:16Z
HIGH

CVE-2021-47966 — PHP: Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-47966

PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid parameter of login.php that allows unauthenticated attackers to extract database contents. Attackers can submit crafted POST requests with SQL payloads using SLEEP functions or RLIKE conditional statements to dump sensitive database information including employee names and credentials. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-15
2026-05-15 19:16Z
CRIT

CVE-2021-47965 — WordPress: Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-47965

WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code execution and complete system compromise. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434VNDWordpressTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-15
2026-05-15 19:16Z
HIGH

CVE-2021-47964 — Schlix: CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-47964

Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager. Attackers can upload a crafted ZIP file containing PHP code in the packageinfo.inc file and trigger execution by accessing the About tab of the installed extension. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDSchlixTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-15
2026-05-15 18:54Z
HIGH

Metasploit Wrap-Up 15/05/2026

Metasploit Framework 6.4.133 release includes four new modules: Marvell QConvergeConsole path traversal (CVE-2025-6793, unauthenticated arbitrary file read), Vim plugin persistence for Linux, GestioIP 3.5.7 authenticated RCE via unsafe upload handler (CVE-2024-48760), and Dolibarr ERP/CRM authenticated PHP injection bypassing tag filters (CVE-2023-30253). The release also adds OptArray datastore option type for multi-valued framework parameters.

SRFApplicationSRFWebOSLinuxSWMetasploitSWDolibarrSWGestioipSWMarvell QconvergeconsoleSWVim
68
Edit Score
2026-05-15
2026-05-15 17:16Z
HIGH

CVE-2026-45035 — Tabby Tabby: This is a zero-click-after-link-visit RCE vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45035

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the handler for the tabby:// URL scheme on all platforms. The URL scheme handler supports a run command that directly executes OS commands with no user confirmation, sanitization, or sandboxing. An attacker can craft a malicious link (tabby://run?command=...) and deliver it via a website, email, chat message, or any other medium. When a victim clicks the link, the CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDTabbyTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-15
2026-05-15 17:16Z
CRIT

CVE-2026-44774 — Traefik Traefik: Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44774

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider handler, bypassing the providers.rest.insecure=false setting. The Gateway provider accepts any TraefikService backend reference whose name ends with @internal, making it possible to route traffic to rest@internal in addition to the intended api@internal. In shared Gate CVSSv3.1 9.9 (CRITICAL)

CWECWE 284VNDTraefikTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-15
2026-05-15 17:16Z
CRIT

CVE-2026-44717 — MCP: Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44717

MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. This vulnerability is fixed in 0.1.1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDMcpTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-15
2026-05-15 17:16Z
CRIT

CVE-2026-41258 — OpenMRS: The VelocityEngine is initialized with only logging properties and noSecureUberspector, leaving the default UberspectImpl

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41258

OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptReferenceRangeUtility.evaluateCriteria() method in OpenMRS Core evaluates database-stored criteria strings as Apache Velocity templates without any sandbox configuration. The VelocityEngine is initialized with only logging properties and noSecureUberspector, leaving the default UberspectImpl in place, which allows unrestricted Java reflection through template CVSSv3.1 9.1 (CRITICAL)

CWECWE 94VNDOpenmrsTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-15
2026-05-15 17:12Z
CRIT

CVE-2026-0300 | Palo Alto Networks PAN-OS Remote Code Execution | Critical Remote Access Risk

Horizon3.ai·horizon3.aiCVE-2026-0300in the wild

CVE-2026-0300 is a critical buffer overflow in Palo Alto Networks PAN-OS User-ID captive portal functionality (CVSS 9.3) allowing unauthenticated remote code execution via specially crafted network packets. The vulnerability requires only network reachability and no authentication; successful exploitation grants attackers firewall-level access to intercept traffic, harvest credentials, modify configurations, and pivot into internal networks. Patches are available across PAN-OS 10.2, 11.1, 11.2, and 12.1 branches; the flaw was added to CISA KEV on May 6, 2026, and exploit code appeared in public repositories by May 15, 2026.

TACTA0001SRFNetwork ApplianceSWPan OsVNDPalo Alto NetworksTYPVulnerabilitySTGInitial AccessTECT1190EXPRce
92
Edit Score
2026-05-15
2026-05-15 16:16Z
CRIT

CVE-2026-45772 — Vercel Turborepo: From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45772

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted repositories that contain malicious Yarn configuration. In affected versions, package manager detection executed yarn --version from the project directory, which could cause Yarn to load and execute a project-controlled yarnPath from .yarnrc.yml. An attacker who controls repository cont CVSSv3.1 9.8 (CRITICAL)

CWECWE 426VNDVercelVNDTurborepoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-15
2026-05-15 16:16Z
HIGH

CVE-2026-35194 — Code: injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35194

Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE expressions with ESCAPE clauses (1.17.0+). User-controlled strings are interpolated into generated Java code without proper escaping, allowing attackers to break out of string literal CVSSv3.1 8.1 (HIGH)

CWECWE 94VNDCodeTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-15
2026-05-15 15:16Z
HIGH

CVE-2026-34253 — This vulnerability occurs in the remote control functionality when processing malformed input, leading to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34253

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution. CVSSv3.1 8.2 (HIGH)

CWECWE 124TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-15
2026-05-15 13:16Z
CRIT

CVE-2026-41553 — Dhtmlx Pdf_export_module: PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41553

PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicious JavaScript code to the parameter whose value is processed by Node.js and subsequently executed. This can lead to server compromise. This issue was fixed in PDF Export Module version 0.7.6. CVSSv3.1 10.0 (CRITICAL)

CWECWE 78VNDPdfVNDDhtmlxTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-15
2026-05-15 10:16Z
HIGH

CVE-2026-41964 — Permission: control vulnerability in the web.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41964

Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability. CVSSv3.1 8.4 (HIGH)

CWECWE 362TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-15
2026-05-15 09:16Z
CRIT

CVE-2026-8398 — Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8398

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally si CVSSv3.1 9.8 (CRITICAL)

CWECWE 506TYPVulnerability
9.8
CVSS v3.1
99
Edit Score