Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v39v-59xw-j98g | Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value |
Thu, 10 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-webui
Open-webui open-webui |
|
| Vendors & Products |
Open-webui
Open-webui open-webui |
Wed, 09 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the shared upcoming-event scheduler compared that value numerically. An authenticated user with the calendar permission could store a non-numeric alert_minutes value that raised an exception and aborted the instance-wide alert pass, suppressing all users' reminders while the event remained in the lookahead window. This issue is fixed in version 0.11.1. | |
| Title | Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value | |
| Weaknesses | CWE-1287 CWE-754 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-10T17:48:20.357Z
Reserved: 2026-09-08T16:44:23.783Z
Link: CVE-2026-87012
Updated: 2026-09-10T17:28:56.987Z
Status : Undergoing Analysis
Published: 2026-09-09T21:17:06.030
Modified: 2026-09-10T18:18:10.610
Link: CVE-2026-87012
No data.
OpenCVE Enrichment
Updated: 2026-09-10T11:00:09Z
Github GHSA