Incorrect authorization in Open WebUI - CVE-2026-88006

 

Incorrect authorization in Open WebUI - CVE-2026-88006

Published: September 28, 2026


Vulnerability identifier: #VU152703
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-88006
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to retain unauthorized access to an existing account.

The vulnerability exists due to incorrect authorization in the OAuth token exchange endpoint in backend/open_webui/routers/auths.py when exchanging a valid provider access token. A remote attacker can exchange a valid, unexpired provider access token to retain access at the account's existing role.

Exploitation requires OAuth token exchange and OAuth role management to be enabled, configured allowed or administrator roles, and an existing account linked to the provider subject or matching email when account merging is enabled.


Affected software

Open WebUI

How to mitigate CVE-2026-88006

Install security update from vendor's website.

Open WebUI - update to 0.11.1

External References

Related Security Bulletins