CVE-2026-0766HIGHEPSS p97.8%
CVE-2026-0766CVE-2026-0766
Description
Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue. https://docs.openwebui.com/security/vendor-dispositions/cve-2026-0766
Scoring
| EPSS | 26.04% probability of exploitation · percentile 97.8% · 2026-09-02T12:00:22Z |
| Published | 2026-01-23 |
| Last modified | 2026-09-02 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Control of Generation of Code ('Code Injection')cwe-94 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.