CVE-2024-7039
CVSS 3.0 Score 8.3 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 269
Summary
CVE-2024-7039 is a newly identified vulnerability in the open-webui/open-webui software version 0.3.8. This issue involves an improper privilege management problem, enabling an attacker who has gained admin access to delete other administrator accounts via the API endpoint `http://0.0.0.0:8080/api/v1/users/{uuid_administrator}`. Despite restrictions in the user interface, this action can be executed through direct API calls, potentially causing significant disruptions in system security.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.