Description
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback enforces. An account whose email domain the login callback would refuse could still obtain a working session through this endpoint. This issue is fixed in version 0.9.0.
Published: 2026-09-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The flaw occurs in the OAuth token exchange path of Open WebUI. When a provider access token is exchanged, the service creates a session even when the user’s email domain is on the deny list or the role policy excludes them. This bypasses the domain allowlist that normally protects users. As a result, an attacker who can obtain a valid provider token can gain access to an account that would otherwise be denied, exposing sensitive content and configuration within the platform.

Affected Systems

Open WebUI versions 0.8.0 through 0.9.0 are affected. Any deployment using these versions and relying on the OAuth token exchange endpoint is at risk until the fix in 0.9.0 is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score is not available and the issue is not listed in KEV, suggesting limited current exploitation. Exploitation requires a provider access token, which can be generated by the attacker or stolen from a legitimate user. The attack vector is remote, using the public token exchange endpoint. Due to the lack of server-side enforcement of the allowlist, the flaw provides unauthorized authentication. Organizations should promptly apply the 0.9.0 update to mitigate.

Generated by OpenCVE AI on September 10, 2026 at 15:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Open WebUI to version 0.9.0 or newer.
  • If upgrade is deferred, disable the OAuth token exchange endpoint or block provider access tokens from untrusted domains.
  • Verify that your configuration enforces the email domain allowlist for all OAuth login flows, including token exchange, before allowing session creation.

Generated by OpenCVE AI on September 10, 2026 at 15:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4qg5-cxx4-g927 Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
History

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Openwebui
Openwebui open Webui
CPEs cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*
Vendors & Products Openwebui
Openwebui open Webui

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Open-webui
Open-webui open-webui
Vendors & Products Open-webui
Open-webui open-webui

Thu, 10 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback enforces. An account whose email domain the login callback would refuse could still obtain a working session through this endpoint. This issue is fixed in version 0.9.0.
Title Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Open-webui Open-webui
Openwebui Open Webui
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:35:40.830Z

Reserved: 2026-09-09T19:19:27.406Z

Link: CVE-2026-88005

cve-icon Vulnrichment

Updated: 2026-09-15T14:35:32.392Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T15:17:55.500

Modified: 2026-09-18T14:44:04.137

Link: CVE-2026-88005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:00:08Z

Weaknesses