CVE-2026-87012

    Dashboard / Vulnerabilities / CVE-2026-87012

    CVE-2026-87012

    Published: 9 Sept 2026Last Modified: 12 Sept 2026

    Summary: Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value

    Details: Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the shared upcoming-event scheduler compared that value numerically. An authenticated user with the calendar permission could store a non-numeric alert_minutes value that raised an exception and aborted the instance-wide alert pass, suppressing all users' reminders while the event remained in the lookahead window. This issue is fixed in version 0.11.1.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- f31768e20e5c6b4f6da0ef657877298b359936cf

    Affected versions

    v0.11.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-87012 | CVE-DB