Incorrect Authorization Affecting open-webui package, versions [0.9.0,0.11.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.51% (42nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-OPENWEBUI-20158703
  • published27 Sept 2026
  • disclosed10 Sept 2026
  • creditUnknown

Introduced: 10 Sep 2026

NewCVE-2026-87014  (opens in a new tab)
CWE-613  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade open-webui to version 0.11.1 or higher.

Overview

open-webui is an Open WebUI

Affected versions of this package are vulnerable to Incorrect Authorization through the caching of user roles on active Socket.IO connections during SSO-driven role changes. An attacker can retain unauthorized read and write access to other users' private notes by maintaining an open socket connection after being demoted from an elevated role via SSO role synchronization. This is only exploitable if SSO role-sync is enabled (either trusted-header authentication with WEBUI_AUTH_TRUSTED_ROLE_HEADER set or OAuth role mapping enabled), and the demotion occurs through the identity provider while the socket connection remains open.

CVSS Base Scores

version 4.0
version 3.1