CVE-2026-70481 is a missing-authorization vulnerability in Open WebUI standard-channel message update and delete handlers affecting versions 0.5.0 through versions before 0.11.0. The handlers validated that a requester held write access to the channel but did not verify that the requester was the author of the target message. Consequently, a member of a shared standard channel could edit or permanently delete messages authored by other channel participants. Group-channel and direct-message handlers enforce authorship checks and are not affected by this behavior.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small Python proof-of-concept set for CVE-2026-70481 affecting Open WebUI standard channels in versions 0.5.0 through 0.10.2. It contains two exploit scripts and one administrator-only lab preparation script. The vulnerability is an authorization flaw in channel message update/delete handling: in standard channels, write permission is incorrectly treated as sufficient for editing or deleting messages authored by other users. As a result, a plain authenticated user with ordinary write access can tamper with, pin, and remove other members' messages while the UI/API continues to attribute edited content to the original author. Repository structure: README.md documents the bug, affected versions, patch behavior in 0.11.0, example API calls, and local Docker-based reproduction steps. prep/lab_setup.py is not an exploit; it provisions a local vulnerable Open WebUI instance by enabling channels, creating admin/victim/attacker users, creating four channels (public vulnerable case, targeted private vulnerable case, readonly control, and group control), seeding messages, and writing lab.json. exploit_channel_message_tamper.py is a guided validation script that demonstrates the main vulnerable case plus controls: successful cross-user edit/pin/delete in standard channels, expected denial in readonly and group-channel cases. exploit_channel_takeover.py is the more aggressive exploit: it authenticates as the attacker, dumps channel history, overwrites a victim message with attacker-controlled content plus arbitrary data/meta, pins another user's message, mass-rewrites all foreign messages, and optionally deletes them all with --wipe. Main exploit capabilities: authenticated low-privilege abuse of Open WebUI REST endpoints to sign in, enumerate channel messages, overwrite victim-authored messages, inject structured fields into those messages, pin foreign messages, and delete foreign messages. The takeover script demonstrates broad integrity impact and limited availability impact. It also includes a stored HTML/JS payload string in message metadata to illustrate downstream abuse potential if rendered unsafely, though the exploit itself is primarily an authorization bypass/message tampering PoC rather than a standalone XSS exploit. Overall, this is a real, operational PoC repository rather than a detection-only script. It is designed for local reproduction against a disposable Open WebUI instance and clearly separates setup from attacker actions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.