CVE-2026-70486Openwebui · Open_webui
Vulnerability data via NVD (ingested)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from the application origin. Any authenticated user with access to a configured terminal server could cause script in a previewed file to run in the Open WebUI origin, read the victim's session token from localStorage, and take over the account, with possible server-side code execution if the victim was an admin or held workspace.functions. This issue is fixed in 0.11.0.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-70486product:"Openwebui Open Webui"http.html:"Open Webui"More intel sources (5)
vuln:CVE-2026-70486vulnerabilities.cve_id: CVE-2026-70486CVE-2026-70486CVE-2026-70486"CVE-2026-70486" exploit -site:nvd.nist.gov