Incorrect authorization in Open WebUI - CVE-2026-88006
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to retain unauthorized access to an existing account.
The vulnerability exists due to incorrect authorization in the OAuth token exchange endpoint in backend/open_webui/routers/auths.py when exchanging a valid provider access token. A remote attacker can exchange a valid, unexpired provider access token to retain access at the account's existing role.
Exploitation requires OAuth token exchange and OAuth role management to be enabled, configured allowed or administrator roles, and an existing account linked to the provider subject or matching email when account merging is enabled.