Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48050 | In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process. |
No reference.
Fri, 11 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-488 NVD-CWE-Other |
|
| CPEs | ||
| Vendors & Products |
Openwebui
Openwebui open Webui |
|
| References |
|
|
| Metrics |
cvssV3_0
|
Fri, 11 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Thu, 17 Oct 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openwebui
Openwebui open Webui |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:* | |
| Vendors & Products |
Openwebui
Openwebui open Webui |
|
| Metrics |
cvssV3_1
|
Thu, 10 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-webui
Open-webui open-webui |
|
| CPEs | cpe:2.3:a:open-webui:open-webui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Open-webui
Open-webui open-webui |
|
| Metrics |
ssvc
|
Thu, 10 Oct 2024 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process. | |
| Title | Exposure of Token in open-webui/open-webui | |
| Weaknesses | CWE-488 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: REJECTED
Assigner: @huntr_ai
Published:
Updated: 2026-09-11T09:21:18.945Z
Reserved: 2024-07-23T19:15:08.148Z
Link: CVE-2024-7049
Updated: 2024-10-10T14:24:52.828Z
Status : Rejected
Published: 2024-10-10T08:15:03.910
Modified: 2026-09-11T10:16:49.593
Link: CVE-2024-7049
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD