Scworld
High-Severity Vulnerability in Open WebUI Exposes Users to Account Takeover
First seen 6 Jan 2026, 18:42 UTC
•


•36.2
Export
Article Content
Browse articles
A high-severity security vulnerability, tracked as CVE-2025-64496, has been identified in Open WebUI, affecting versions 0.6.34 and older when the Direct Connections feature is enabled. Discovered by Cato Networks researchers, the flaw allows for account takeover and, under certain conditions, remote code execution on backend servers due to unsafe handling of server-sent events.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
Clop Hackers Exploit Oracle Zero-Day, Breaching Barts Health NHS and Dartmouth Data
Data Breach at University of Phoenix Due to Oracle EBS Zero-Day Exploit
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows
Cisco Secure Email Gateway Targeted by Advanced Persistent Threat
Logitech Confirms Data Breach Linked to Clop Extortion Gang