Description
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking that they were still active or still had features.automations, and check_model_access only enforced private-model grants for the exact user role, allowing deactivated pending users to continue scheduled model execution. This issue is fixed in version 0.10.0.
Published: 2026-07-09
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Open WebUI versions 0.9.0 through the pre‑0.10.0 releases occurs when the execute_automation routine rehydrates automation owners without rechecking that those owners are still active or possess the required automation permissions. At the same time, the check_model_access logic only applies private‑model grants for the exact user role, meaning a deactivated pending user can still trigger scheduled automations that run private models. This authorization bypass enables the attacker to access private models and potentially leak sensitive data or consume resources they should not be able to use.

Affected Systems

Any self‑hosted Open WebUI installation running a vulnerable version – specifically 0.9.0 up to but not including 0.10.0 – is affected. The fix was introduced in release 0.10.0, which added a re‑validation step for user status and model ACLs at the start of automation execution, preventing deactivated pending users from running automated tasks.

Risk and Exploitability

The CVSS score of 3.1 indicates low severity, and the EPSS score of <1% indicates a very low exploitation probability. The vulnerability is not listed in CISA KEV. An attacker would need to obtain or create a deactivated pending user that still retains automation permissions; once such an account exists, the automated process can be triggered, allowing the attacker to execute private models without proper authorization. The exploitation requirements are specific and not trivial, which contributes to the low risk rating.

Generated by OpenCVE AI on July 29, 2026 at 12:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Open WebUI to version 0.10.0 or later, where active‑status and model ACL checks are enforced before executing automations.
  • Disable or delete scheduled automations belonging to deactivated pending users to prevent legacy executions.
  • Recreate or remove pending user accounts to ensure that revoked status does not retain automation or model access privileges.

Generated by OpenCVE AI on July 29, 2026 at 12:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mvx4-532p-xfm9 Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
History

Thu, 09 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Open-webui
Open-webui open-webui
Vendors & Products Open-webui
Open-webui open-webui

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking that they were still active or still had features.automations, and check_model_access only enforced private-model grants for the exact user role, allowing deactivated pending users to continue scheduled model execution. This issue is fixed in version 0.10.0.
Title Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Weaknesses CWE-285
CWE-862
CWE-863
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Open-webui Open-webui
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-09T18:08:30.890Z

Reserved: 2026-07-02T21:05:02.925Z

Link: CVE-2026-59226

cve-icon Vulnrichment

Updated: 2026-07-09T18:05:16.284Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:30:03Z

Weaknesses