CVE-2026-59218
MEDIUMOpen WebUI: Account enumeration via observable login timing discrepancy
Title source: cnaDescription
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the /api/v1/auths/signin endpoint looked users up by email and only ran bcrypt password verification when a credential existed, making registered-account attempts measurably slower than missing-email attempts and allowing unauthenticated account enumeration. This issue is fixed in version 0.10.0.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/open-webui/open-webui/security/advisories/GHSA-7rw5-9f7q-xj36
X_Refsource_Misc x_refsource_misc
https://github.com/open-webui/open-webui/pull/26385
X_Refsource_Misc x_refsource_misc
https://github.com/open-webui/open-webui/commit/993e74912199c66c522f08ec81abe31d76985e39
X_Refsource_Misc x_refsource_misc
https://github.com/open-webui/open-webui/releases/tag/v0.10.0
Scores
CVSS v3
5.3
EPSS
0.0024
EPSS Percentile
15.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-208
Status
published
Products (3)
open-webui/open-webui
< 0.10.0
openwebui/open_webui
< 0.10.0
pypi/open-webui
0 - 0.10.0PyPI
Published
Jul 09, 2026
Tracked Since
Jul 09, 2026