Insufficient Session Expiration in Open WebUI - #VU152708
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to execute commands on the terminal server after account deactivation.
The vulnerability exists due to insufficient session expiration in the terminal proxy WebSocket route when using an already open terminal WebSocket after the user's access is withdrawn. A remote user can send commands through the existing terminal connection to execute commands on the terminal server after account deactivation.
A terminal server must be configured, the user must have been granted access to it, and the terminal session must be open when the user's role is changed to pending.