CVE-2026-28788: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-28788 is an authorization bypass vulnerability in Open WebUI, a self-hosted AI platform, that allows any authenticated user to overwrite arbitrary files via the POST /api/v1/retrieval/process/files/batch endpoint. The vulnerability affects all versions prior to 0.8.6 (i.e., ≤ 0.8.5) and was disclosed on March 26, 2026. It carries a CVSS v3.1 base score of 7.1 (High) (GitHub Advisory, Open WebUI Advisory).

Technical details

The root cause is CWE-639 (Authorization Bypass Through User-Controlled Key), classified as OWASP API1:2023 Broken Object Level Authorization. The process_files_batch() function in backend/open_webui/routers/retrieval.py was designed as an internal helper called by the knowledge base router after performing ownership checks, but it is also exposed as a standalone HTTP endpoint (@router.post(...)) that only requires get_verified_user — any authenticated user — with no ownership verification before writing. An attacker first enumerates file UUIDs via GET /api/v1/knowledge/{id}/files (available to any user with read access to a shared knowledge base), then submits a POST /api/v1/retrieval/process/files/batch request with attacker-controlled content and the target file UUID, causing Files.update_file_by_id() to overwrite the file without checking that file.user_id == user.id (Open WebUI Advisory, GitHub Advisory).

Impact

Successful exploitation enables RAG (Retrieval-Augmented Generation) poisoning: overwritten file content is served directly to the LLM, allowing the attacker to control what the model tells every user querying the affected knowledge base, including injecting adversarial instructions that the model may follow (e.g., via code interpreter or function calling). The original file content is permanently and silently replaced with no audit trail or notification to the file owner. Any multi-user Open WebUI deployment with shared knowledge bases is at risk, and the attacker requires only a valid account of any role (Open WebUI Advisory).

Exploitability

A proof-of-concept exploit script (poc_exploit.py) is publicly documented in the official security advisory, using only Python 3's standard library (urllib) and requiring no special tooling. The PoC authenticates as a low-privileged attacker, overwrites a target file via the batch endpoint, and verifies RAG poisoning by confirming the attacker's canary string appears in LLM responses. The EPSS score is approximately 0.036%, and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of disclosure (Open WebUI Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a target Open WebUI instance (version ≤ 0.8.5) and obtain a valid user account with read access to at least one shared knowledge base.
  2. Enumerate file UUIDs: Authenticate and send GET /api/v1/knowledge/{kb_id}/files using the attacker's JWT token. The response returns metadata for all files in the knowledge base, including their UUIDs.
  3. Craft the overwrite payload: Prepare a POST request to POST /api/v1/retrieval/process/files/batch with the target file UUID and attacker-controlled content (e.g., a canary string like BOLA-<unique_marker> or malicious instructions).
  4. Execute the exploit: Run python3 poc_exploit.py --url http://<host>:3000 --file-id <target-file-uuid> -t <attacker-jwt>. The script submits the batch request, which overwrites the target file's content in the database without any ownership check.
  5. Verify RAG poisoning: Log in as another user, attach the poisoned knowledge base to a chat session, and query the document. The LLM response will include the attacker's injected content, confirming successful RAG poisoning (Open WebUI Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to /api/v1/retrieval/process/files/batch originating from non-admin user accounts or from accounts that do not own the referenced file UUIDs; GET requests to /api/v1/knowledge/{id}/files from users who do not normally access that endpoint.
  • Logs: API access logs showing a low-privileged user account calling POST /api/v1/retrieval/process/files/batch with file IDs not belonging to that user; repeated enumeration of knowledge base file listings (GET /api/v1/knowledge/*/files) from a single account.
  • File System / Database: Unexpected changes to file content in the Open WebUI database with no corresponding admin or owner action; file hashes (SHA-256) updated without a legitimate upload event.
  • LLM Behavior: Unusual or unexpected content appearing in LLM responses referencing knowledge base documents, particularly strings inconsistent with the original document content (Open WebUI Advisory).

Mitigation and workarounds

Upgrade Open WebUI to version 0.8.6 or later, which patches the issue by adding ownership checks in the process_files_batch() endpoint before any file write operation (Open WebUI Advisory, GitHub Advisory). As an interim workaround for deployments that cannot immediately upgrade, restrict access to shared knowledge bases and monitor or block direct calls to POST /api/v1/retrieval/process/files/batch from non-admin users at the network or API gateway level. Audit existing knowledge base files for unexpected content changes as part of incident response.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management