Insertion of Sensitive Information Into Sent Data in Open WebUI - CVE-2026-87015
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to obtain user session credentials.
The vulnerability exists due to improper handling of connection-specific cookie jars in the tool loading routine in backend/open_webui/utils/tools.py when processing a tool call with multiple external tool servers. A remote attacker can operate a bearer-authenticated tool server configured by an administrator to obtain user session credentials.
A user must trigger a tool call. Exploitation requires at least two attached tool servers, including a session or system OAuth connection that is processed last.