Impact
The vulnerability occurs because the OAuth token exchange endpoint in Open WebUI bypasses role validation run during normal OAuth login. A user whose provider roles would normally be refused or demoted can still obtain a session using this endpoint, effectively bypassing authorization controls. The flaw allows an attacker who can obtain a provider access token to encrypt a session that matches the existing role at the time of token exchange. This yields improper authorization, potentially granting access to resources the user is not entitled to.
Affected Systems
Affected systems are Open WebUI deployments running version 0.8.0 through 0.11.1 inclusive. The product is the open-webui application, with the range of affected releases specified by the vendor. No other versions are impacted according to the CVE, and newer releases contain the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the vulnerability is not listed in CISA KEV. EPSS data is unavailable, so the likelihood of exploitation cannot be quantified. The likely attack path is over the network to the OAuth token exchange endpoint, and the attacker must possess a valid provider access token. Because the endpoint does not re‑run OAuth role checks, the attack is straightforward for anyone who can trick a user into providing a provider access token or who can directly obtain one, making the threat real for environments that rely on strict role enforcement.
OpenCVE Enrichment
Github GHSA