Description
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback runs. A user whose provider roles the login callback would refuse, or would demote, could still obtain a working session at their existing role through this endpoint. This issue is fixed in version 0.11.1.
Published: 2026-09-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass via OAuth Token Exchange
Action: Patch Now
AI Analysis

Impact

The vulnerability occurs because the OAuth token exchange endpoint in Open WebUI bypasses role validation run during normal OAuth login. A user whose provider roles would normally be refused or demoted can still obtain a session using this endpoint, effectively bypassing authorization controls. The flaw allows an attacker who can obtain a provider access token to encrypt a session that matches the existing role at the time of token exchange. This yields improper authorization, potentially granting access to resources the user is not entitled to.

Affected Systems

Affected systems are Open WebUI deployments running version 0.8.0 through 0.11.1 inclusive. The product is the open-webui application, with the range of affected releases specified by the vendor. No other versions are impacted according to the CVE, and newer releases contain the fix.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, and the vulnerability is not listed in CISA KEV. EPSS data is unavailable, so the likelihood of exploitation cannot be quantified. The likely attack path is over the network to the OAuth token exchange endpoint, and the attacker must possess a valid provider access token. Because the endpoint does not re‑run OAuth role checks, the attack is straightforward for anyone who can trick a user into providing a provider access token or who can directly obtain one, making the threat real for environments that rely on strict role enforcement.

Generated by OpenCVE AI on September 10, 2026 at 18:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Open WebUI to version 0.11.1 or later, which includes the OAuth role check in the token exchange flow.
  • Restrict access to the OAuth token exchange endpoint by firewall or application configuration so only trusted services can call it.
  • Revoke all existing provider access tokens and force users to re‑authenticate through the legitimate OAuth login route.

Generated by OpenCVE AI on September 10, 2026 at 18:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wvm9-9g5j-623f Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
History

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Openwebui
Openwebui open Webui
CPEs cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*
Vendors & Products Openwebui
Openwebui open Webui

Fri, 11 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Open-webui
Open-webui open-webui
Vendors & Products Open-webui
Open-webui open-webui

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback runs. A user whose provider roles the login callback would refuse, or would demote, could still obtain a working session at their existing role through this endpoint. This issue is fixed in version 0.11.1.
Title Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Open-webui Open-webui
Openwebui Open Webui
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-10T17:46:41.061Z

Reserved: 2026-09-09T19:19:27.406Z

Link: CVE-2026-88006

cve-icon Vulnrichment

Updated: 2026-09-10T17:45:58.760Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T15:17:55.783

Modified: 2026-09-18T14:43:56.117

Link: CVE-2026-88006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:00:08Z

Weaknesses