Skip to content
Threat Feed

Tag

Webui

4 briefs RSS
high advisory

Open WebUI: Realtime Endpoints Fail to Revoke JWTs

Open WebUI versions from 0.9.0 to before 0.10.0, when configured with Redis, fail to correctly enforce JWT revocation for realtime authentication endpoints such as Socket.IO and terminal websockets, allowing attackers to maintain access to real-time features with stolen, revoked JWTs.

Open WebUI vulnerability jwt authentication webui realtime bypass
1t 1c
medium advisory

HCL BigFix WebUI Information Disclosure Vulnerabilities

A remote, authenticated attacker can exploit multiple vulnerabilities in HCL BigFix WebUI applications to disclose sensitive information.

BigFix WebUI information-disclosure webui hcl
2r 1t
critical advisory

Pelican Web UI Privilege Escalation Vulnerability

A privilege escalation vulnerability in Pelican WebUI versions v7.21 to v7.24 allows authenticated users to gain admin privileges by manipulating database records, potentially leading to configuration modification, API token creation, and password changes.

pelicanplatform/pelican +1 privilege-escalation webui pelican
2r 1t 1i
high advisory

Hermes WebUI Arbitrary File Deletion Vulnerability (CVE-2026-6832)

Hermes WebUI is vulnerable to arbitrary file deletion via path traversal in the /api/session/delete endpoint due to insufficient validation of the session_id parameter, allowing authenticated attackers to delete writable JSON files on the host system.

cve-2026-6832 path-traversal file-deletion webui
2r 1t 1c