THREAT OPS › Threat News › [GHSA] GHSA-rq84-p6rr-vf89 (high) — Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
[GHSA] GHSA-rq84-p6rr-vf89 (high) — Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
GHSA-rq84-p6rr-vf89 Severity: high CVE: CVE-2026-70482
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
## Summary
The OAuth token exchange endpoint accepts a raw provider access token and validates it by calling the provider's userinfo endpoint. A userinfo endpoint reports only that a token is valid, never which OAuth client it was issued to, and the
Indicators of compromise
- CVE-2026-70482cve
- victim@corp.exampleemail
Original source: https://github.com/advisories/GHSA-rq84-p6rr-vf89