CVE-2026-59218
EUVD-2026-4261709.07.2026, 17:17
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the /api/v1/auths/signin endpoint looked users up by email and only ran bcrypt password verification when a credential existed, making registered-account attempts measurably slower than missing-email attempts and allowing unauthenticated account enumeration. This issue is fixed in version 0.10.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openwebui | open_webui | 𝑥 < 0.10.0 |
𝑥
= Vulnerable software versions