CVE-2026-56400
â ī¸ highSummary
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them.
CVSS Score
8.3
High
EPSS Score
0.3
Exploit Probability
Published Date
2026-07-15
First Seen: 2026-07-16
đ Relative Risk Intelligence
This CVE is High Risk - more severe than 79.5% of all 338,292 vulnerabilities in our database.
#69,198
Top 25% most severe
Severity Percentile
đ¯ CISA SSVC Assessment Updated: Jul 15, 2026
đ Exploitation Status
Poc
Proof-of-concept available
âī¸ Automatable
NO
Requires human interaction
đĨ Technical Impact
Total
Complete system compromise possible
SSVC data provided by
CISA
Last Modified
2026-07-16
Source
NVD đ
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS Vector 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)