Insufficient Session Expiration in Open WebUI - #VU152708

 

Insufficient Session Expiration in Open WebUI - #VU152708

Published: September 28, 2026


Vulnerability identifier: #VU152708
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute commands on the terminal server after account deactivation.

The vulnerability exists due to insufficient session expiration in the terminal proxy WebSocket route when using an already open terminal WebSocket after the user's access is withdrawn. A remote user can send commands through the existing terminal connection to execute commands on the terminal server after account deactivation.

A terminal server must be configured, the user must have been granted access to it, and the terminal session must be open when the user's role is changed to pending.


Affected software

Open WebUI

Remediation

Install security update from vendor's website.

Open WebUI - update to 0.11.4

External References

Related Security Bulletins