
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0766 is a code injection vulnerability in Open WebUI, specifically within the load_tool_module_by_id function, that allows authenticated remote attackers to execute arbitrary code. The vulnerability was reported to the vendor on October 9, 2025, but the vendor closed the report without providing a fix, leading ZDI to publish it as a 0-day advisory on January 9, 2026. The affected version is Open WebUI 0.6.32. It carries a CVSS v3.0 base score of 8.8 (High), assigned by Zero Day Initiative (ZDI Advisory).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection): the load_tool_module_by_id function passes user-supplied input directly into a Python code execution context without adequate validation or sanitization (ZDI Advisory). An authenticated attacker can craft a malicious string that, when processed by this function, causes arbitrary Python code to be executed server-side. The attack vector is network-based, requires low privileges (valid authentication), no user interaction, and has low attack complexity. A technical write-up and PoC exploit script have been published by researcher bitt0n on GitHub (GitHub PoC) and additional analysis is available from community researchers (Infinitsec).
Successful exploitation grants an attacker arbitrary code execution in the context of the Open WebUI service account, resulting in high impact to confidentiality, integrity, and availability of the affected system (ZDI Advisory). An attacker can read sensitive data (including AI model configurations, API keys, and user data), modify system configurations, install backdoors, and disrupt service availability. The compromise of the service account may also enable lateral movement within the hosting environment depending on the account's privileges.
A proof-of-concept exploit has been publicly released by researcher bitt0n on GitHub (GitHub PoC), and the ZDI advisory was published as a 0-day due to the vendor's failure to remediate the issue (ZDI Advisory). As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.0068 (0.68%), indicating a currently low but non-negligible probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.
load_tool_module_by_id function.load_tool_module_by_id, causing the server to execute the injected Python code.load_tool_module_by_id with unexpected input strings; authentication events from unfamiliar IP addresses.bash, sh, curl, wget, python3 with unusual arguments); new cron jobs or scheduled tasks created under the service account.As of the advisory publication date, no vendor patch is available; the Open WebUI vendor closed the original vulnerability report without providing a fix (ZDI Advisory). The primary recommended mitigation is to restrict network access to Open WebUI instances to trusted users and networks only, using firewalls or network-level access controls. Organizations should consider isolating affected Open WebUI deployments, enforcing strong authentication, and monitoring for suspicious activity until a patch becomes available. Users should follow ZDI and Open WebUI project channels for patch announcements.
The ZDI published this as a 0-day advisory after the vendor failed to respond adequately to repeated follow-ups over a three-month disclosure period, highlighting concerns about the vendor's vulnerability response process (ZDI Advisory). The vulnerability received coverage from The Hacker Wire and community discussion on Mastodon/Infosec.Exchange, with researchers noting the risk of unanswered disclosures in AI tooling platforms (The Hacker Wire). A Medium post and GitHub PoC from researcher bitt0n further amplified community awareness of the issue.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."