SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityRejected

CVE-2026-0766

Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a…

UnscoredEPSS —

Does this matter?

Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.

Description

Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue. https://docs.openwebui.com/security/vendor-dispositions/cve-2026-0766

CVSS
Not yet scored
EPSS
No score yet
CISA KEV
Not listed
Source
zdi-disclosures@trendmicro.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.