Improper neutralization of wildcards or matching symbols in Open WebUI - CVE-2026-87016
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to another user's account.
The vulnerability exists due to improper neutralization of wildcard characters in the OAuth subject and SCIM external-ID lookup functions when resolving externally supplied identity values on SQLite. A remote attacker can supply a subject claim containing SQL wildcard characters to gain unauthorized access to another user's account.
Deliberate OAuth or OIDC exploitation requires the configured subject claim to be user-settable. PostgreSQL deployments are not affected.