Incorrect authorization in Open WebUI - #VU152705
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to retain access to resources permitted by their existing role.
The vulnerability exists due to incorrect authorization in the OAuth token exchange endpoint and OAuth role policy when exchanging a provider access token for an Open WebUI session. A remote user can exchange a valid provider access token after their provider role no longer satisfies the allowed-role policy to retain access to resources permitted by their existing role.
Exploitation requires OAuth token exchange and OAuth role management to be enabled, an allowed-role configuration that does not contain a wildcard, a provider that supplies roles only in the ID token, and a previously linked account.