A AegiFlow
MEDIUMCVSS 5.3EPSS 0.3%

CVE-2026-0767

Withdrawn Advisory: Open WebUI/ZDI-CAN-28259

Published
2026-01-23
Modified
2026-09-02
EPSS percentile
17%
Aliases
GHSA-vh96-p962-544h
Sources
github-advisory

Summary

### Withdrawn Advisory This advisory has been withdrawn because it does not describe a valid vulnerability. This link is maintained to preserve external references. ### Original Description Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Open WebUI. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of credentials provided to the endpoint. The issue results from transmitting sensitive information in plaintext. An attacker can leverage this vulnerability to disclose transmitted credentials, leading to further compromise. Was ZDI-CAN-28259.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIopen-webui

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.