Open WebU's investigation showed that this describes the behavior of plain HTTP rather than a defect in the product. TLS termination is the operator's deployment decision, as it is for any backend that speaks HTTP, and not a security issue. https://docs.openwebui.com/security/vendor-dispositions/cve-2026-0767
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Verify whether a newer Open WebUI release contains a fix that encrypts credential transmission; if available, upgrade to that version.
- Limit network access to the credential endpoint with firewall rules or network segmentation so only trusted hosts can reach it.
- Enforce encrypted transport (HTTPS/TLS) for all authentication traffic, ensuring that the endpoint does not accept cleartext requests over unencrypted connections.
Generated by OpenCVE AI on April 18, 2026 at 03:16 UTC.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vh96-p962-544h | Withdrawn Advisory: Open WebUI/ZDI-CAN-28259 |
No reference.
Wed, 02 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-319 | |
| CPEs | ||
| Vendors & Products |
Openwebui
Openwebui open Webui |
|
| References |
|
|
| Metrics |
cvssV3_0
|
Wed, 02 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Open WebUI. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of credentials provided to the endpoint. The issue results from transmitting sensitive information in plaintext. An attacker can leverage this vulnerability to disclose transmitted credentials, leading to further compromise. Was ZDI-CAN-28259. | Open WebU's investigation showed that this describes the behavior of plain HTTP rather than a defect in the product. TLS termination is the operator's deployment decision, as it is for any backend that speaks HTTP, and not a security issue. https://docs.openwebui.com/security/vendor-dispositions/cve-2026-0767 |
Fri, 30 Jan 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openwebui
Openwebui open Webui |
|
| CPEs | cpe:2.3:a:openwebui:open_webui:0.6.32:*:*:*:*:*:*:* | |
| Vendors & Products |
Openwebui
Openwebui open Webui |
|
| Metrics |
cvssV3_1
|
Fri, 23 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-webui
Open-webui open-webui |
|
| Vendors & Products |
Open-webui
Open-webui open-webui |
Fri, 23 Jan 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Open WebUI. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of credentials provided to the endpoint. The issue results from transmitting sensitive information in plaintext. An attacker can leverage this vulnerability to disclose transmitted credentials, leading to further compromise. Was ZDI-CAN-28259. | |
| Title | Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability | |
| Weaknesses | CWE-319 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: REJECTED
Assigner: zdi
Published:
Updated: 2026-09-02T17:34:15.123Z
Reserved: 2026-01-08T22:50:10.918Z
Link: CVE-2026-0767
Updated: 2026-01-23T16:33:47.579Z
Status : Rejected
Published: 2026-01-23T04:16:03.660
Modified: 2026-09-02T18:19:00.897
Link: CVE-2026-0767
No data.
OpenCVE Enrichment
Updated: 2026-04-18T03:30:25Z
No weakness.
Github GHSA