
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28788 is an authorization bypass vulnerability in Open WebUI, a self-hosted AI platform, that allows any authenticated user to overwrite arbitrary files via the POST /api/v1/retrieval/process/files/batch endpoint. The vulnerability affects all versions prior to 0.8.6 (i.e., ≤ 0.8.5) and was disclosed on March 26, 2026. It carries a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, Open WebUI Advisory).
The root cause is CWE-639 (Authorization Bypass Through User-Controlled Key), classified as OWASP API1:2023 Broken Object Level Authorization. The process_files_batch() function in backend/open_webui/routers/retrieval.py was designed as an internal helper called by the knowledge base router after performing ownership checks, but it is also exposed as a standalone HTTP endpoint (@router.post(...)) that only requires get_verified_user — any authenticated user — with no ownership verification before writing. An attacker first enumerates file UUIDs via GET /api/v1/knowledge/{id}/files (available to any user with read access to a shared knowledge base), then submits a POST /api/v1/retrieval/process/files/batch request with attacker-controlled content and the target file UUID, causing Files.update_file_by_id() to overwrite the file without checking that file.user_id == user.id (Open WebUI Advisory, GitHub Advisory).
Successful exploitation enables RAG (Retrieval-Augmented Generation) poisoning: overwritten file content is served directly to the LLM, allowing the attacker to control what the model tells every user querying the affected knowledge base, including injecting adversarial instructions that the model may follow (e.g., via code interpreter or function calling). The original file content is permanently and silently replaced with no audit trail or notification to the file owner. Any multi-user Open WebUI deployment with shared knowledge bases is at risk, and the attacker requires only a valid account of any role (Open WebUI Advisory).
A proof-of-concept exploit script (poc_exploit.py) is publicly documented in the official security advisory, using only Python 3's standard library (urllib) and requiring no special tooling. The PoC authenticates as a low-privileged attacker, overwrites a target file via the batch endpoint, and verifies RAG poisoning by confirming the attacker's canary string appears in LLM responses. The EPSS score is approximately 0.036%, and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of disclosure (Open WebUI Advisory, GitHub Advisory).
GET /api/v1/knowledge/{kb_id}/files using the attacker's JWT token. The response returns metadata for all files in the knowledge base, including their UUIDs.POST /api/v1/retrieval/process/files/batch with the target file UUID and attacker-controlled content (e.g., a canary string like BOLA-<unique_marker> or malicious instructions).python3 poc_exploit.py --url http://<host>:3000 --file-id <target-file-uuid> -t <attacker-jwt>. The script submits the batch request, which overwrites the target file's content in the database without any ownership check.POST requests to /api/v1/retrieval/process/files/batch originating from non-admin user accounts or from accounts that do not own the referenced file UUIDs; GET requests to /api/v1/knowledge/{id}/files from users who do not normally access that endpoint.POST /api/v1/retrieval/process/files/batch with file IDs not belonging to that user; repeated enumeration of knowledge base file listings (GET /api/v1/knowledge/*/files) from a single account.Upgrade Open WebUI to version 0.8.6 or later, which patches the issue by adding ownership checks in the process_files_batch() endpoint before any file write operation (Open WebUI Advisory, GitHub Advisory). As an interim workaround for deployments that cannot immediately upgrade, restrict access to shared knowledge bases and monitor or block direct calls to POST /api/v1/retrieval/process/files/batch from non-admin users at the network or API gateway level. Audit existing knowledge base files for unexpected content changes as part of incident response.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."