Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the shared upcoming-event scheduler compared that value numerically. An authenticated user with the calendar permission could store a non-numeric alert_minutes value that raised an exception and aborted the instance-wide alert pass, suppressing all users' reminders while the event remained in the lookahead window. This issue is fixed in version 0.11.1. | |
| Title | Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value | |
| Weaknesses | CWE-1287 CWE-754 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-09T20:57:58.794Z
Reserved: 2026-09-08T16:44:23.783Z
Link: CVE-2026-87012
No data.
Status : Received
Published: 2026-09-09T21:17:06.030
Modified: 2026-09-09T21:17:06.030
Link: CVE-2026-87012
No data.
OpenCVE Enrichment
No data.