Aug 4, 2026·7 min read·111 visits
Authenticated collaborators with write access to a shared folder can delete subfolders owned by others, triggering a cascading deletion of the folder owner's private chat history.
A critical broken access control vulnerability in Open WebUI (v0.10.0 to v0.11.0) allows authenticated write-collaborators to delete shared subfolders they do not own. Because deletion triggers a backend cascade using the folder owner's identity, this results in unauthorized permanent deletion of the owner's nested chats, messages, and files.
The vulnerability resides in the backend routing component of Open WebUI, specifically within the delete_folder_by_id handler located in backend/open_webui/routers/folders.py. This handler manages the removal of directories used to organize conversational assets and files. Open WebUI provides collaboration features allowing users to share folders with other team members, exposing an API attack surface accessible to authenticated network clients.
This flaw represents a broken authorization vulnerability classified under CWE-862 (Missing Authorization) and CWE-863 (Incorrect Authorization). The application fails to restrict subfolder deletion privileges exclusively to the folder's creator or system administrators. Instead, authorization checks fallback to evaluating write privileges, which are automatically inherited by collaborators on nested folders.
An authenticated collaborator with write access can issue a delete command targeting subfolders owned by another user. When executed, the backend uses the folder owner's identity to run cascading database deletions, recursively purging the owner's conversations, messages, and associated attachments.
This security issue affects deployments running Open WebUI from version v0.10.0 up to but excluding v0.11.0. The vulnerability is resolved in version v0.11.0 by enforcing that only the original folder owner or a global administrator can authorize folder removal.
The root cause of this vulnerability lies in an architectural separation between root folder access validation and subfolder access validation. In the collaborative model of Open WebUI, write permissions propagate from parent folders down to nested subfolders. Consequently, granting a user write permissions on a shared parent folder implicitly grants them write access to all downstream subfolders.
In the vulnerable implementation of the DELETE /api/v1/folders/{id} endpoint, the logic first attempts to locate the target folder based on the request initiator's user ID. If the initiator is not the folder owner, the query returns nothing. At this stage, instead of throwing an access denied error, the application falls back to check if the target folder has a defined parent_id attribute.
If the folder has a parent ID (making it a subfolder), the system executes a permissive authorization check: await _has_folder_access(user.id, folder, 'write', db). This check is intended to allow write-collaborators to edit and add records inside the directory. However, the system incorrectly treats the destructive action of folder deletion as a standard write operation, bypassing strict ownership requirements.
Furthermore, the backend deletion process triggers a database cascade. To maintain internal database integrity, the backend retrieves the folder owner's ID (folder.user_id) to execute the database purge. Because the cascade is bound to the owner's context, an unauthorized collaborator's request initiates recursive deletions across the owner's private dataset, destroying their chat and document associations.
An analysis of the patch code illustrates the exact conditional branching that led to the vulnerability. The pre-patch logic in backend/open_webui/routers/folders.py contained a bifurcated authorization verification structure that checked for subfolder status and administrative privileges separately:
# Pre-Patch Vulnerable Logic
if not folder:
# Check if it is a shared subfolder with write access
folder = await Folders.get_folder_by_id(id, db=db)
if folder and folder.parent_id:
# High-risk branch: permits non-owners with write access to delete subfolders
if user.role != 'admin' and not await _has_folder_access(user.id, folder, 'write', db):
raise HTTPException(
status_code=status.HTTP_403_FORBIDDEN,
detail=ERROR_MESSAGES.ACCESS_PROHIBITED,
)
elif folder and not folder.parent_id:
# Root shared folders can only be deleted by owner/admin
if user.role != 'admin':
raise HTTPException(
status_code=status.HTTP_403_FORBIDDEN,
detail=ERROR_MESSAGES.ACCESS_PROHIBITED,
)The vulnerability was resolved in commit 915ef7d0798d3175819cedbb2f62d7bf0db78c98 by completely removing this nested conditional block. The updated logic removes the permissive write-access validation and ensures that folder deletion is strictly guarded by ownership or administration privileges:
# Post-Patch Remediated Logic
if not folder:
# Deletion cascades into the owner's data, so only the owner or an admin may delete
folder = await Folders.get_folder_by_id(id, db=db)
if not folder:
raise HTTPException(
status_code=status.HTTP_404_NOT_FOUND,
detail=ERROR_MESSAGES.NOT_FOUND,
)
if user.role != 'admin':
raise HTTPException(
status_code=status.HTTP_403_FORBIDDEN,
detail=ERROR_MESSAGES.ACCESS_PROHIBITED,
)The remediated code establishes a safe hierarchy. If the requesting user does not own the folder, the application fetches the folder by its ID. If the folder exists, the request initiator must have the administrator role to proceed. If the initiator is not an administrator, the handler raises a 403 Forbidden exception, effectively blocking any unauthorized collaborator from executing the deletion cascade.
Exploitation of CVE-2026-70494 requires low-privileged network access to the target Open WebUI instance. The attacker must first be added as a collaborator to a shared folder with write permissions. This workspace configuration allows the attacker's session token to inherit write access to all subfolders created within that directory.
Once the collaborator access is established, the attacker identifies the database identifier of the victim's subfolder. This information is typically exposed during standard directory listing actions or client-side layout rendering. With the target ID, the attacker constructs a direct HTTP request to the vulnerable endpoint.
DELETE /api/v1/folders/<target_subfolder_id> HTTP/1.1
Host: openwebui.example.local
Authorization: Bearer <attacker_jwt_session_token>
Content-Type: application/json
{
"delete_contents": true
}The diagram below outlines the logical divergence between the vulnerable and remediated authorization checks when handling this deletion request:
If the request is sent with the delete_contents parameter set to true, the database engine processes a cascade that recursively deletes all nested chat histories and associated documents owned by the victim. If delete_contents is false, the subfolder is deleted, and the victim's files are orphaned and moved to the root workspace.
The impact of this vulnerability affects the integrity and availability of organizational data. Because Open WebUI functions as an interface for managing institutional knowledge and model training context, the deletion of curated folders can disrupt workflows. The destruction of chat histories and files results in a permanent loss of audit trails and documentation.
An attacker can perform this action silently, requiring no interaction from the targeted folder owner. Since the backend cascade utilizes the folder owner's identity to run the deletion sequence, the application's access log records the deletion as a structural change, masking the collaborator's unauthorized initiation.
The CVSS v3.1 rating is calculated as 8.1 (High) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H. The high availability and integrity impacts indicate that the vulnerability leads to data loss. The requirement for authenticated collaborator privileges lowers the vector's privilege rating to Low (PR:L), but the lack of complexity (AC:L) makes the exploit reliable.
To eliminate the vulnerability, administrators must deploy Open WebUI version v0.11.0 or higher. This release integrates the patch that restricts folder deletion to owners and administrators. The update can be deployed by pulling the latest container images from the official distribution registry.
For instances where immediate version upgrades are restricted due to operational verification policies, a manual patch can be applied to the folder router file. Administrators can access the underlying container filesystem and modify backend/open_webui/routers/folders.py. Replacing the branching logic with a strict administrator validation block mirrors the official upstream fix.
# Manual Hotpatch Override
if not folder:
folder = await Folders.get_folder_by_id(id, db=db)
if not folder or user.role != 'admin':
raise HTTPException(
status_code=status.HTTP_403_FORBIDDEN,
detail=ERROR_MESSAGES.ACCESS_PROHIBITED
)Following any hotpatch or upgrade, security teams should execute authorization testing. Verify that a user assigned write permissions on a shared parent folder receives a 403 Forbidden status code when attempting to delete subfolders belonging to other users. Additionally, monitor system logging to ensure that deletion requests are audited and restricted to authorized sessions.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H| Product | Affected Versions | Fixed Version |
|---|---|---|
Open WebUI Open WebUI | >= v0.10.0, < v0.11.0 | v0.11.0 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-862 (Missing Authorization) / CWE-863 (Incorrect Authorization) |
| Attack Vector | Network (Remote) |
| CVSS v3.1 Score | 8.1 (High) |
| EPSS Score | Not Available |
| Impact | Data Destruction / Loss of Chat History |
| Exploit Status | POC-Conceptual |
| CISA KEV Status | Not Listed |
The application does not perform an authorization check on the subfolder deletion code path to verify if the request initiator is the owner of the resource or an administrator.
An origin trust boundary failure in the Ruby mechanize library (prior to v2.14.1) allows unauthenticated remote web servers to harvest sensitive global request headers, such as Authorization Bearer tokens and cookies, by utilizing HTML-level meta-refresh redirection tags. Standard HTTP-level redirect boundaries were not applied to document-level redirects, creating a vector for cross-origin credential leakage during automated crawls.
CVE-2026-107718 is a medium-severity Open Redirect vulnerability in the core HTTP server package of the AdonisJS Node.js framework. Prior to versions 8.2.3 and 9.3.0, the framework built route paths by directly interpolating dynamic parameters and wildcard segments without URI encoding. If an application routes attacker-controlled input directly to a dynamic first path segment and uses the generated route URL as a redirect destination, a leading slash can produce a scheme-relative external URL. Modern web browsers process scheme-relative URLs by redirecting the client to the specified external domain, exposing users to credential harvesting, social engineering, and session hijacking. This vulnerability affects all applications running unpatched configurations where input validation is not explicitly implemented before generating paths.
CVE-2026-107725 is a critical security bypass in Hazelcast where missing authorization checks in the MapPermission class permit unprivileged clients to issue queries containing aggregators or projections. This architectural oversight allows attackers to run arbitrary code on the cluster servers under the privileges of the active Hazelcast process.
A stored Cross-Site Scripting (XSS) vulnerability was identified in Indico, an open-source event management system developed at CERN, prior to version 3.3.13. The vulnerability stems from weak URL validation in custom link fields and lack of HTML sanitization during Marshmallow serialization of event notes. This allows authenticated attackers with event modification privileges to inject malicious payloads that execute in the browser of users viewing the event pages or collaborating on notes.
A technical analysis of CVE-2026-107397, a stored Cross-Site Scripting (XSS) vulnerability in Indico's collaborative notes editor and custom link generation fields. Prior to version 3.3.13, Marshmallow serialization schemas omitted HTML sanitization during conflict resolution, and form validators failed to enforce strict URI schemes, enabling authenticated low-privilege attackers to execute arbitrary JavaScript.
An authorization bypass vulnerability exists in the legacy session export API of Indico, an open-source event management system developed at CERN. Due to a missing object-level access check, authenticated users can bypass configuration-level restrictions to extract private session metadata (including session titles, descriptions, and list of conveners) from events that they are otherwise authorized to view.