← All CVEs

CVE-2026-0766

unscored

Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue. https://docs.openwebui.com/security/vendor-dispositions/cve-2026-0766

CVSS
26.0%
EPSS (exploit prob.)
98th
EPSS percentile
2026-01-23
Published

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-0766