Improper Authentication Affecting open-webui package, versions [0.6.41,0.11.1)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.6% (47th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-OPENWEBUI-20158700
  • published27 Sept 2026
  • disclosed10 Sept 2026
  • creditUnknown

Introduced: 10 Sep 2026

NewCVE-2026-87016  (opens in a new tab)
CWE-155  (opens in a new tab)
CWE-287  (opens in a new tab)

How to fix?

Upgrade open-webui to version 0.11.1 or higher.

Overview

open-webui is an Open WebUI

Affected versions of this package are vulnerable to Improper Authentication in the get_user_by_oauth_sub or get_user_by_scim_external_id process. An attacker can gain unauthorized access to another user's account, including administrator accounts, by supplying specially crafted OAuth subject claim values containing SQL wildcard characters. This is only exploitable if the deployment uses SQLite as the database backend and the OAuth subject claim is mapped to a user-controlled value, or if a legitimate subject value contains an underscore, which can cause accidental account mismatches. For the SCIM path, the attacker must already possess the SCIM bearer token.

CVSS Base Scores

version 4.0
version 3.1