Incorrect authorization in Open WebUI - #VU152705

 

Incorrect authorization in Open WebUI - #VU152705

Published: September 28, 2026


Vulnerability identifier: #VU152705
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to retain access to resources permitted by their existing role.

The vulnerability exists due to incorrect authorization in the OAuth token exchange endpoint and OAuth role policy when exchanging a provider access token for an Open WebUI session. A remote user can exchange a valid provider access token after their provider role no longer satisfies the allowed-role policy to retain access to resources permitted by their existing role.

Exploitation requires OAuth token exchange and OAuth role management to be enabled, an allowed-role configuration that does not contain a wildcard, a provider that supplies roles only in the ID token, and a previously linked account.


Affected software

Open WebUI

Remediation

Install security update from vendor's website.

Open WebUI - update to 0.11.4

External References

Related Security Bulletins